Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

65 results about "Multiple attack" patented technology

Coupling network asynchronous dynamic intermittent safety control method and system

The embodiment of the invention provides a coupling network asynchronous dynamic intermittent safety control method and system, and the method comprises the steps: obtaining multiple attack signals comprising an injection attack signal and a replacement attack signal after building a dynamic model of a following network, a target network and a state error variable; and setting an intermittent controller according to the dynamic network model and the multiple attack signals, and setting a dynamic mechanism based on an exponential function to convert a state error variable into an interval control function. Wherein the interval control function is used for realizing security mean square synchronization control between the following network model and the target network model. According to the method, the asynchronous anti-attack intermittent dynamic cooperative control strategy oriented to the complex coupled network can be constructed based on an average intermittent control rate and dynamic event trigger threshold coupling method by utilizing a node self-adaptive dual spoofing attack probability model, and the problems of difficulty in multi-attack modeling and insufficient control strategy collaboration can be relieved.
Owner:CHANGSHU INSTITUTE OF TECHNOLOGY

Network monitoring with multiple attack graphs

A computer-implemented method for monitoring a computer network is provided, the method comprising: storing a first attack graph, the attack graph comprising a plurality of nodes each representing an event that may occur within the computer network; storing one or more predetermined variation properties of one or more of the events represented by the nodes, the variation properties being indicative of possible changes to the nodes within the first attack graph; determining a plurality of possible alternative sequences of the nodes in the first attack graph based on the variation properties; generating a plurality of additional attack graphs, each of the additional attack graphs comprising a plurality of the nodes of the first attack graph arranged in one of the possible sequences; and monitoring events within the network to detect a set of events occurring in a sequence that corresponds to one of the additional attack graphs to identify a potential security attack. A computer system including at least one processor and memory storing computer program code configured to perform the said method, and a computer program or computer readable medium comprising instructions that when executed by a computer system cause the computer system to perform the said method are also provided.
Owner:BRITISH TELECOM PLC

Large model output data security detection method and system based on adversarial attack

The invention discloses a large model output data security detection method and system based on adversarial attacks. The method comprises the following steps: constructing and optimizing a strategy space containing a plurality of attack strategies, and grading and sorting the strategies to improve the attack efficiency; generating a single-strategy antagonism prompt by the attack model according to the optimized strategy space, and performing effectiveness evaluation and feedback correction on the prompt by the judgment model; inputting a prompt passing the evaluation into the target large model to obtain a response, and performing malicious degree scoring on the response by the judgment model; and if the single-strategy attack is not successful, introducing an optimization mechanism based on a genetic algorithm, generating a more complex multi-strategy antagonism prompt through strategy variation and crossover, and carrying out iterative attack until the target large model is successfully broken into the prison. According to the method, the security defects of the large model can be efficiently and comprehensively detected in a self-adaptive and multi-strategy attack mode.
Owner:CHINA ACADEMY OF INFORMATION & COMM

A method and system for asynchronous dynamic intermittent safety control of coupled networks

The embodiment of the present application provides a method and system for asynchronous dynamic intermittent safety control of a coupled network. The method can obtain multiple attack signals including injection attack signals and replacement attack signals after establishing a dynamic model of a follower network, a target network, and a state error variable, and set an intermittent controller according to the dynamic network model and the multiple attack signals, and then set a dynamic mechanism based on an exponential function to convert the state error variable into an interval control function. The interval control function is used to achieve safe mean square synchronization control between the follower network model and the target network model. The method can utilize a node-adaptive double deception attack probability model, based on the average intermittent control rate and the dynamic event trigger threshold coupling method, to construct an asynchronous anti-attack intermittent dynamic collaborative control strategy for complex coupled networks, which can alleviate the difficulties in modeling multiple attacks and the lack of coordination of control strategies.
Owner:CHANGSHU INSTITUTE OF TECHNOLOGY

Chinese big language model security evaluation system and method based on dynamic extension and bottom-taking mechanism

The invention provides a Chinese large language model safety evaluation system and method based on dynamic extension and a bottom-taking mechanism, and belongs to the field of natural language processing and artificial intelligence. On the basis of an existing benchmark test data set, an attack test data set is generated by combining a large language model with multiple attack methods, and attack test data is generated for a request rejected to respond by the model by utilizing a fine-tuned expert model through a bottom-out mechanism; constructing a corresponding false positive test data set, inputting the attack test data set and the false positive test data set into the Chinese large language model to be evaluated, and reasoning to obtain an output result; and finally, carrying out multi-dimensional evaluation on an output result and automatically generating a report. The method has good expandability and adaptability, a test data set can be dynamically expanded, emerging security threats can be followed up, and anaphylaxis and generation of harmful content can be effectively avoided; and a more flexible, comprehensive and efficient solution is provided for security assessment of the Chinese large language model.
Owner:PEKING UNIV +1

Attack data generation and large model training method and device, equipment and storage medium

The invention provides an attack data generation and large model training method and device, equipment and a storage medium, and belongs to the technical field of artificial intelligence, and the method comprises the steps: inputting guide content into an attack language model to obtain an attack prompt, determining the attack prompt with the highest attack success rate as a target attack, and collecting attack data related to the target attack prompt. According to the method, the attack language model is excited by the initial guide content to generate diversified attack prompts, and the most effective attack prompt is screened out based on the attack success rate to serve as the target attack prompt for data collection, so that various attack prompts can be automatically generated, and the workload of manually designing the attack prompts is reduced; in addition, the validity and quality of the collected attack data can be ensured through a screening mechanism, and a rich and accurate data basis is provided for subsequent model security evaluation and attack strategy optimization, so that potential vulnerabilities of the target language model can be found more comprehensively, and the security and reliability of the model are improved.
Owner:HEFEI IFLY DIGITAL TECH CO LTD

Method and system for testing QinQ network security, terminal and storage medium

The invention belongs to the technical field of network security detection, and particularly relates to a QinQ network security test method and system, a terminal and a storage medium, and the method comprises the steps: constructing a QinQ network security test environment comprising an attack simulation module, a traffic monitoring module and a security evaluation module; the method comprises the following steps: generating a test data packet containing multiple attack types through an attack simulation module, injecting the test data packet into a to-be-tested QinQ network, collecting processing behavior data of the QinQ network on the test data packet in real time through a flow monitoring module, analyzing the processing behavior data through a security evaluation module, and generating a security score and a vulnerability report of the QinQ network; s4, optimizing a label verification mechanism and an access control strategy of the QinQ network according to the vulnerability report, and repeatedly executing the steps S2 to S4 until the security score reaches a preset threshold value; and the security protection capability of the QinQ network on a label processing layer can be comprehensively detected.
Owner:SHANDONG CHAOYUE DATA CONTROL ELECTRONICS CO LTD

Identification method and device for attack path of vehicle, vehicle and storage medium

The invention relates to a recognition method and device for an attack path of a vehicle, the vehicle and a storage medium, and the method comprises the steps: generating a data flow diagram of a target vehicle through the system data of the target vehicle, defining components in the data flow diagram, so as to determine a dependency relationship and attributes between the components, converting the data flow diagram into an attribute diagram in combination with the dependency relationship and attributes; inputting the attribute graph into a pre-constructed path recognition model to obtain a plurality of attack paths of the target vehicle; and carrying out attack feasibility scoring on the plurality of attack paths, and bringing the high-risk attack paths meeting a preset high feasibility condition into a calculation pool so as to screen out a target attack path from the calculation pool. Therefore, the technical problems that in the related technology, for a complex data flow diagram, part of attack paths are easy to omit through manual identification, so that the finally identified attack path is not necessarily optimal, the formulation of final security measures is influenced, and the network security of the vehicle is not favorably guaranteed are solved.
Owner:GUANGZHOU AUTOMOBILE GROUP CO LTD

Network attack identification method, device and electronic equipment

The present disclosure relates to a network attack identification method and device and electronic equipment, and relates to the technical field of network security, wherein the method comprises: acquiring network security data of a network asset, constructing a knowledge graph of the network asset based on the network security data, and performing detection rule conversion processing based on the knowledge graph to generate corresponding attack detection rules; detecting whether the rule features of the attack detection rules can correctly identify attack behaviors or abnormal behaviors, and detecting whether the rule coverage of the attack detection rules meets the expected detection target; if the rule features can correctly identify attack behaviors or abnormal behaviors, and the rule coverage meets the expected detection target, then attack subgraphs for different network assets are generated based on the attack detection rules, so as to identify network attacks against different network assets by using multiple attack subgraphs. Through the present scheme, attack behaviors of specific assets can be effectively associated, and threats and attack scenarios faced by specific assets can be comprehensively understood.
Owner:CHINA MOBILE GROUP SICHUAN +1

A network attack defense method, device, intrusion detection equipment, and storage medium.

This application provides a network attack defense method, apparatus, intrusion detection device, and storage medium. Applied to an intrusion detection device, the device maintains multiple attack rules, each labeled with an attack chain tag. The attack chain tag indicates the attack chain to which the attack rule belongs. The method includes: performing intrusion detection on network traffic to determine a first attack rule that the network traffic has hit; the first attack rule is labeled with a target attack chain tag; querying at least one second attack rule labeled with the target attack chain tag from the multiple attack rules; sending the first and second attack rules belonging to the same attack chain to a firewall, so that the firewall performs attack defense according to a protection policy; the protection policy is generated based on the first and second attack rules. The firewall can also perform pre-defense against subsequent attack behaviors based on the attack rules associated with the attack chain, thereby improving the firewall's defense effectiveness.
Owner:BEIJING TOPSEC NETWORK SECURITY TECH +2

Attack prediction model training method and device of power secondary system and computer equipment

The invention relates to an attack prediction model training method and device of a power secondary system, computer equipment, a computer readable storage medium and a computer program product. The method comprises the following steps: generating a plurality of pieces of attack chain data according to attack alarm data of each security device in the power secondary system; taking the last attack action information in each piece of attack chain data as a target label of each piece of attack chain data, and taking other attack action information in each piece of attack chain data as input data of each piece of attack chain data; the other attack action information is attack action information except the last attack action information in each piece of attack chain data; and taking each piece of attack chain data as a training sample, and training the attack prediction model of the power secondary system according to the target label and the input data to obtain the trained attack prediction model of the power secondary system. By adopting the method, the prediction performance of the prediction model on multi-step attacks can be improved.
Owner:ELECTRIC POWER RES INST CHINA SOUTHERN POWER GRID CO LTD

A network attack scenario reconstruction method based on device fingerprint in 5G private network scenario

The present invention relates to the technical field of digital information transmission, and in particular to a method for reconstructing a network attack scenario based on device fingerprints in a 5G private network scenario, which includes the following steps: capturing the traffic that triggers the alarm and storing it as a pcap package, generating a list of data packets corresponding to each IP address and traffic; marking the network flow through a five-tuple of <source address, destination address, source port, destination port, timestamp>; extracting the direction and length of the traffic in the network flow as a temporary fingerprint; extracting temporary fingerprints with similar time from a fingerprint database, determining the twin IP, and thus outputting a twin IP list of the attacked IP address; searching for related attack fragments based on the twin IP list, associating multiple attack fragments, and reconstructing the attack scenario. The present invention can associate multiple attack fragments and restore the complete attack scenario without relying on the access rights of the control plane network element, thereby helping analysts to carry out analysis activities such as attack classification and attack prediction.
Owner:POWERCHINA BEIJING ENG CORP

Modeling cyberspace operations and operation effectiveness

A method, system, and computer-readable media for modeling cyberspace operations and the effects thereof. Network and connectivity data for an operational environment model may be retrieved from a network scan. Likelihood data that a network element takes a plurality of possible configurations may be mapped. Determination of a probability of effect of a capability acting on the network element may be based on the likelihood data and uncertainties associated with the capability. Multiple attacks within the operational environment model may be modeled to determine an attack path therethrough. Functional modeling techniques to model functional impacts of attacks on an operational environment model are also disclosed.
Owner:APPLIED RESEARCH ASSOCIATES INC

Attack detection method and device, equipment and storage medium

The invention belongs to the technical field of terminal security, and discloses an attack detection method and device, equipment and a storage medium. According to the method, the process behavior of the target process is matched with the initial detection condition of each preset attack behavior chain; if the initial detection condition is successfully matched with the initial detection condition of any preset attack behavior chain, taking the successfully matched preset attack behavior chain as a target behavior chain; constructing a detection condition list according to the target behavior chain; and if the subsequent process behavior of the target process meets each detection condition in the detection condition list, judging that the high-risk attack is detected. The process behaviors of the processes in the terminal are monitored and matched with the multiple attacks included in the preset attack behavior chains corresponding to the advanced threat programs, so that it is ensured that the terminal can find whether high-risk attacks exist or not in advance, misjudgment of single behavior detection is avoided, and the safety of the terminal is improved. Therefore, the terminal can automatically detect whether the attack exists or not, and the dependence on the server is reduced.
Owner:BEIJING HONGTENG INTELLIGENT TECH CO LTD

A few-shot attack pattern recognition method based on a large language model

The application provides a few-shot attack mode recognition method based on a large language model, comprising: constructing a classification prompt for recognizing a to-be-recognized attack behavior data instance to obtain a coarse classification label; constructing a pseudo-instance generation prompt for generating a pseudo-instance related to the coarse classification label; combining the to-be-recognized attack behavior data instance, the coarse classification label and the pseudo-instance to construct a few-shot reference example; obtaining a fine classification label according to the few-shot reference example; and sorting the fine classification label to obtain a relevance sorting result of an attack mode recognition label and the to-be-recognized attack behavior data instance. The method improves the recognition accuracy of complex and rare attack modes through the construction of a few-shot classification reference example and the recognition of a fine classification label. The method can recognize multiple attack mode recognition labels related to a specific attack behavior from multiple-source heterogeneous attack behavior data, and improves the accuracy and flexibility of attack behavior threat analysis.
Owner:GUANGZHOU UNIVERSITY

Communication resource allocation method based on master-slave game

The invention discloses a communication resource allocation method based on a master-slave game, and belongs to the technical field of communication, and the method comprises the steps: building a master-slave game model between a system model and a multi-attack model through optimizing an attack strategy and a defense strategy; according to the defense strategy, the attack strategy set and the attack revenue function, taking defense revenue minimization as a first optimization target, and calculating an optimal attack strategy; according to the optimal attack strategy, the defense strategy set and the defense revenue function, by taking defense revenue maximization as a second optimization target, calculating an optimal defense strategy; and solving a second optimization target to obtain an equilibrium solution of the master-slave game model, determining a synchronization coefficient of a tie line, constructing a coefficient matrix of a state space of a control region, and calculating a control gain which enables the control region to be asymptotically stable. The problems that in the prior art, when an attack occurs, a resource allocation strategy cannot be adjusted in time, and attack damage is difficult to defend are solved.
Owner:NANJING UNIV OF POSTS & TELECOMM

Web application firewall vulnerability detection method, device and system based on load variation injection

The invention belongs to the technical field of network security, and particularly relates to a Web application firewall vulnerability detection method based on load variation injection. Comprising the following steps: constructing a unified attack grammar rule base covering multiple attack types; analyzing the original attack load into an abstract syntax tree; carrying out semantic reservation load variation based on the syntax tree to generate a semantic equivalent variation load; performing protection rule detection on the Web application firewall, analyzing a detection result and performing pruning operation on the syntax tree; a Monte Carlo tree search algorithm is utilized, a rule detection mechanism is combined, and a variation path with a high success rate is dynamically evaluated and preferentially tested so as to efficiently generate an antagonistic load capable of bypassing WAF detection; according to the method, the problems of attack failure, low black box test efficiency and insufficient coverage of a single attack type caused by semantic destruction in the prior art are solved, and the WAF rule base vulnerability can be systematically evaluated.
Owner:CHONGQING UNIV OF POSTS & TELECOMM

Bionic multi-weapon fighting robot

The utility model relates to the technical field of fighting robots, and provides a bionic multi-weapon fighting robot which comprises a robot body, walking wheels, a driving mechanism, weapon arms, first motors and attack wheels, the walking wheels are rotationally connected to the robot body, the two first motors are arranged above the front ends of the two weapon arms respectively, and the driving mechanism is connected with the attack wheels. The first motor is in driving connection with the attack wheels, a plurality of oblique teeth are arranged on the circumferences of the attack wheels at intervals, the two attack wheels are located below the front ends of the two weapon arms correspondingly, impact blocks are arranged at the front ends of the weapon arms, the rear ends of the two weapon arms are hinged to the front end of the machine body correspondingly, and the driving mechanism is arranged on the machine body. The driving mechanism is in driving connection with the two weapon arms and used for driving the two weapon arms to be close to and separated from each other. The attack function that clamping attack is carried out through the two weapon arms, grinding or smashing and other damage is carried out through the attack wheel is achieved, the attack diversity is improved, multiple attack actions are carried out at the same time, and the attack effectiveness is also guaranteed.
Owner:HEILONGJIANG XUANSU TECHNOLOGY CO LTD

A voiceprint spoofing defense method, device and computer readable storage medium

PendingCN122372302ASound sourcesDecision model
A method, apparatus, and computer-readable storage medium for voiceprint spoofing defense include: acquiring a speech signal to be verified; extracting multi-dimensional features from the speech signal to obtain a multi-dimensional feature vector, wherein the multi-dimensional feature vector includes at least speech text content features, identity features, sound quality features representing recording or synthesis traces, liveness features representing the physiological characteristics of the sound source, and adversarial perturbation features; fusing the multi-dimensional feature vector to obtain a joint feature vector; inputting the joint feature vector into a pre-trained joint risk decision model to obtain a spoofing risk score; and determining the verification result of the speech signal to be verified based on the comparison result of the spoofing risk score and a preset threshold. This application can effectively detect multiple attack modes such as replay attacks, speech synthesis attacks, and adversarial example attacks simultaneously; and accurately detect high-quality spoofing attacks.
Owner:XIANGYANG DAAN AUTOMOBILE TEST CENT

A data processing method, apparatus, device, and machine-readable storage medium

The present disclosure provides a data processing method, apparatus, device, and machine-readable storage medium, the method comprising: receiving security alarm logs; grouping security alarm logs associated with the same attack source IP into a group, calculating the attack characteristics associated with the attack source IP associated with each security alarm log in the group according to preset rules based on the security alarm logs in the same group; performing clustering calculations based on the attack characteristics associated with each attack source IP, and obtaining an attacker profile based on the calculation results. Through the technical solution of the present disclosure, the security alarms reported by the security device are analyzed based on the attack events of each attack source, and the attack behavior characteristics of the attack source on a single target are extracted. The attack behavior of the attack source on multiple attack targets is then calculated and analyzed, and the attack behavior characteristics of the attack source are extracted. On this basis, each attack source is classified using clustering calculations, and finally an attacker profile is obtained, which is efficient and accurate.
Owner:NEW H3C SECURITY TECH CO LTD

Accuracy in attack technique labeling in an extended detection system

Techniques for providing a confidence rating for an attack technique tag and a guidance for improving the confidence rating are described. An attack technique analytics engine receives telemetry data, a notification that an attack has been detected using an attack detection source, the notification including an attack technique tag indicating an attack technique used in the attack, and attack technique data including a likelihood of a particular attack technique, from among multiple attack techniques, occurring determined using a particular attack detection source from among multiple attack detection sources. Based on the telemetry, the attack technique tag, and the attack technique data, a confidence rating that the attack corresponds to the attack technique is determined. The attack detection source and attack technique are analyzed to determine a guidance for improving the confidence rating, and the rating and guidance are appended to the attack technique tag.
Owner:CISCO TECHNOLOGY INC

Ammunition for forming aerial barrage

PCT designated stageWO2026176278A1Classical mechanicsPropeller
The ammunition is used on a drone interceptor to combat other drones. The ammunition fires a propeller snare. Ammunition comprises multiple charges with separate electric activation for a multiple attack possibility. The rope forms an air barrier from the moment the shot is fired, it allows the target's propeller to become entangled at a short distance. Twisting the rope increases the likelihood of entanglement on the target. The design of the projectile reduces the likelihood of ricochet. Projectile filled with extra length of rope, it increases the likelihood of entangling the target's propeller. The ammunition is attached to the activation unit. The activation unit is attached to the weapon carrier. The low weight of the weapon allows it to be used on small interceptor drone.
Owner:ZAICEVSKIJ ALEKSEJ

Network monitoring with multiple attack graphs

A computer-implemented method for monitoring a computer network is provided, the method comprising: storing a first attack graph, the attack graph comprising a plurality of nodes each representing an event that may occur within the computer network; storing one or more predetermined variation properties of one or more of the events represented by the nodes, the variation properties being indicative of possible changes to the nodes within the first attack graph; determining a plurality of possible alternative sequences of the nodes in the first attack graph based on the variation properties; generating a plurality of additional attack graphs, each of the additional attack graphs comprising a plurality of the nodes of the first attack graph arranged in one of the possible sequences; and monitoring events within the network to detect a set of events occurring in a sequence that corresponds to one of the additional attack graphs to identify a potential security attack. A computer system including at least one processor and memory storing computer program code configured to perform the said method, and a computer program or computer readable medium comprising instructions that when executed by a computer system cause the computer system to perform the said method are also provided.
Owner:BRITISH TELECOM PLC

Emergency response tissue toughness evaluation method and system based on complex network

The invention belongs to the technical field of emergency response, and particularly discloses an emergency response tissue toughness evaluation method and system based on a complex network. Comprising the following steps: constructing an organizational relation matrix according to actual response data and emergency plan data so as to establish a relation and an interaction mechanism among subjects in an emergency response process; constructing an organization network of four stages of pre-disaster plan, emergency rescue, recovery and reconstruction and post-disaster plan according to the organization relation matrix; the node importance is evaluated; the method comprises the following steps: simulating a network operation condition under a single attack strategy to perform toughness evaluation on a network organization of residual efficiency characterization emergency response; coupling a plurality of network attack strategies by utilizing an entropy weight method, further simulating different high-hazard risk scenes, and calculating the weight of each attack strategy by calculating information entropy; and evaluating the network efficiency under various attack scenes to obtain the overall toughness level of the emergency response organization in each stage. The method can clearly reflect the emergency response capability and recovery capability of the tissue in different stages.
Owner:CHINA UNIV OF GEOSCIENCES (WUHAN)

Simulated attack data processing method and device, electronic equipment and storage medium

The embodiment of the invention provides a simulation attack data processing method and device, electronic equipment and a storage medium, and the method comprises the steps: firstly, obtaining a simulation attack strategy corresponding to a simulation attack request in response to the simulation attack request of a virtual system; then, based on an attack scene description language, performing stage standardization processing on the simulation attack strategy to obtain multi-stage description data, the multi-stage description data comprising standardized description data of a plurality of attack stages; secondly, on the basis of system parameters of the virtual system, generating a virtual container corresponding to each piece of standardized description data, executing an attack action in each virtual container on the basis of the corresponding standardized description data, and obtaining feedback data in the execution process; and finally, vulnerability data of the virtual system is obtained based on the feedback data, and a risk assessment result of the virtual system is obtained based on the vulnerability data and the feedback data, so that the standard of simulation attack description in the attack and defense drilling process is improved, and the accuracy of attack and defense drilling assessment is improved.
Owner:PENG CHENG LAB

Network security risk identification method and device, storage medium and electronic equipment

The invention discloses a network security risk identification method and device, a storage medium and electronic equipment. Relates to the field of network security detection, and the method comprises the steps: obtaining endogenous threat intelligence data of a to-be-detected network device, the endogenous threat intelligence data comprising risk scores corresponding to a plurality of attack source IPs; multiple pieces of external threat intelligence data are obtained, the multiple pieces of external threat intelligence data are in one-to-one correspondence with the multiple data sources, and the external threat intelligence data comprise original malicious probabilities corresponding to multiple attack source IPs obtained under the corresponding data sources; the original malicious probability represents the probability that the corresponding attack source IP obtained under the corresponding data source is a malicious attack IP; and determining a network security identification result of the to-be-tested network device based on the endogenous threat intelligence data and the plurality of external threat intelligence data. According to the invention, the technical problem of low network security risk identification accuracy in related technologies is solved.
Owner:AGRICULTURAL BANK OF CHINA

A power distribution network black box adversarial sample generation method based on large language model topology reasoning guidance

The application discloses a power distribution network black box confrontation sample generation method based on a large language model topology reasoning guide, which comprises the following steps: determining an attack target of a scheduling task, quantifying a destructive intention of an attacker, and converting a fuzzy attack target into a multi-target attack loss function; using general knowledge and reasoning ability of the large language model, screening out key nodes with the highest attack cost performance, and obtaining a mask vector; under the constraint of the mask vector, generating a specific disturbance vector for a continuous domain or a discrete domain; and performing sample verification. The application introduces a large language model as a topology cognition engine, uses semantic reasoning ability of the large language model to screen out key fragile nodes in a power distribution network, generates an attack mask, and guides a black box optimizer to lock a key subspace through the mask, so that high-quality confrontation samples covering multiple attack targets and action domain types are efficiently generated without accessing an internal structure of the model, and rich robustness training data is provided for intelligent agents.
Owner:XIANGTAN UNIV +1

Decision-making method based on network defense agent

The invention relates to a decision-making method based on a network defense agent, which relates to the field of network security, and comprises the following steps: constructing a network system topological graph based on a connection relationship of network equipment; matching network threats conforming to node attributes on nodes of the network system topological graph by using the generated sigma rule, thereby automatically constructing an attack action space corresponding to any node in the network system topological graph; constructing a plurality of attack agents and defense agents; the intelligent agent comprises a decision network and an evaluation network; the decision network gives an action probability according to the observed local network environment state, and selects an action according to the action probability; the evaluation network evaluates the combined network environment state observed by all the attack agents to obtain the value of a strategy or an execution action; and training an attack agent and a defense agent by utilizing reinforcement learning, and carrying out network defense decision by utilizing the trained defense agent so as to cope with dynamic network attacks.
Owner:JIANGSU RUINING XINCHUANG TECH CO LTD

Liveness detection method and system

The live body detection method and system provided in the specification, after obtaining a target user image of a target user, inputting the target user image into a live body detection model to obtain an attack probability of each attack type in multiple attack types and a clue probability of at least one attack clue corresponding to each attack type, the live body detection model comprising a model obtained after decoupling learning of a feature space according to attack types, and determining a live body detection result of the target user based on the attack probability and the clue probability, and outputting the live body detection result; the scheme can improve the accuracy of live body detection.
Owner:ALIPAY (HANGZHOU) INFORMATION TECH CO LTD

Security defense method, system and device for controller area network bus and medium

The embodiment of the invention provides a security defense method, system and equipment for a controller area network bus, and a medium, and belongs to the field of communication security of the controller area network bus. The method comprises the following steps: collecting bus communication behavior data through a trusted monitoring node; the method comprises the following steps: acquiring a pre-shared key, constructing a network security threat knowledge graph based on the pre-shared key, generating a dynamic inter-frame interval sequence for each message ID to be sent on a bus based on the pre-shared key and a pseudo-random function, and adjusting at least one defense parameter according to a potential attack path output by the knowledge graph; before a sending node is controlled to send messages, a credible monitoring node calculates legal sending time windows of all the messages based on the same dynamic inter-frame interval sequence; and controlling the trusted monitoring node to monitor the bus, and if the occurrence time of the start bit of the message is detected to be earlier than the legal sending time window, judging that the time sequence is illegal. Microsecond-level real-time active defense covering multiple attack types is achieved, and meanwhile the real-time performance of key messages is guaranteed through dynamic scheduling.
Owner:SINO TRUK JINAN POWER CO LTD