Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

45 results about "Multiple attack" patented technology

Large model output data security detection method and system based on adversarial attack

The invention discloses a large model output data security detection method and system based on adversarial attacks. The method comprises the following steps: constructing and optimizing a strategy space containing a plurality of attack strategies, and grading and sorting the strategies to improve the attack efficiency; generating a single-strategy antagonism prompt by the attack model according to the optimized strategy space, and performing effectiveness evaluation and feedback correction on the prompt by the judgment model; inputting a prompt passing the evaluation into the target large model to obtain a response, and performing malicious degree scoring on the response by the judgment model; and if the single-strategy attack is not successful, introducing an optimization mechanism based on a genetic algorithm, generating a more complex multi-strategy antagonism prompt through strategy variation and crossover, and carrying out iterative attack until the target large model is successfully broken into the prison. According to the method, the security defects of the large model can be efficiently and comprehensively detected in a self-adaptive and multi-strategy attack mode.
Owner:CHINA ACADEMY OF INFORMATION & COMM

Attack data generation and large model training method and device, equipment and storage medium

The invention provides an attack data generation and large model training method and device, equipment and a storage medium, and belongs to the technical field of artificial intelligence, and the method comprises the steps: inputting guide content into an attack language model to obtain an attack prompt, determining the attack prompt with the highest attack success rate as a target attack, and collecting attack data related to the target attack prompt. According to the method, the attack language model is excited by the initial guide content to generate diversified attack prompts, and the most effective attack prompt is screened out based on the attack success rate to serve as the target attack prompt for data collection, so that various attack prompts can be automatically generated, and the workload of manually designing the attack prompts is reduced; in addition, the validity and quality of the collected attack data can be ensured through a screening mechanism, and a rich and accurate data basis is provided for subsequent model security evaluation and attack strategy optimization, so that potential vulnerabilities of the target language model can be found more comprehensively, and the security and reliability of the model are improved.
Owner:HEFEI IFLY DIGITAL TECH CO LTD

Method and system for testing QinQ network security, terminal and storage medium

The invention belongs to the technical field of network security detection, and particularly relates to a QinQ network security test method and system, a terminal and a storage medium, and the method comprises the steps: constructing a QinQ network security test environment comprising an attack simulation module, a traffic monitoring module and a security evaluation module; the method comprises the following steps: generating a test data packet containing multiple attack types through an attack simulation module, injecting the test data packet into a to-be-tested QinQ network, collecting processing behavior data of the QinQ network on the test data packet in real time through a flow monitoring module, analyzing the processing behavior data through a security evaluation module, and generating a security score and a vulnerability report of the QinQ network; s4, optimizing a label verification mechanism and an access control strategy of the QinQ network according to the vulnerability report, and repeatedly executing the steps S2 to S4 until the security score reaches a preset threshold value; and the security protection capability of the QinQ network on a label processing layer can be comprehensively detected.
Owner:SHANDONG CHAOYUE DATA CONTROL ELECTRONICS CO LTD

Identification method and device for attack path of vehicle, vehicle and storage medium

The invention relates to a recognition method and device for an attack path of a vehicle, the vehicle and a storage medium, and the method comprises the steps: generating a data flow diagram of a target vehicle through the system data of the target vehicle, defining components in the data flow diagram, so as to determine a dependency relationship and attributes between the components, converting the data flow diagram into an attribute diagram in combination with the dependency relationship and attributes; inputting the attribute graph into a pre-constructed path recognition model to obtain a plurality of attack paths of the target vehicle; and carrying out attack feasibility scoring on the plurality of attack paths, and bringing the high-risk attack paths meeting a preset high feasibility condition into a calculation pool so as to screen out a target attack path from the calculation pool. Therefore, the technical problems that in the related technology, for a complex data flow diagram, part of attack paths are easy to omit through manual identification, so that the finally identified attack path is not necessarily optimal, the formulation of final security measures is influenced, and the network security of the vehicle is not favorably guaranteed are solved.
Owner:GUANGZHOU AUTOMOBILE GROUP CO LTD

Network attack identification method, device and electronic equipment

The present disclosure relates to a network attack identification method and device and electronic equipment, and relates to the technical field of network security, wherein the method comprises: acquiring network security data of a network asset, constructing a knowledge graph of the network asset based on the network security data, and performing detection rule conversion processing based on the knowledge graph to generate corresponding attack detection rules; detecting whether the rule features of the attack detection rules can correctly identify attack behaviors or abnormal behaviors, and detecting whether the rule coverage of the attack detection rules meets the expected detection target; if the rule features can correctly identify attack behaviors or abnormal behaviors, and the rule coverage meets the expected detection target, then attack subgraphs for different network assets are generated based on the attack detection rules, so as to identify network attacks against different network assets by using multiple attack subgraphs. Through the present scheme, attack behaviors of specific assets can be effectively associated, and threats and attack scenarios faced by specific assets can be comprehensively understood.
Owner:CHINA MOBILE GROUP SICHUAN +1

A network attack defense method, device, intrusion detection equipment, and storage medium.

This application provides a network attack defense method, apparatus, intrusion detection device, and storage medium. Applied to an intrusion detection device, the device maintains multiple attack rules, each labeled with an attack chain tag. The attack chain tag indicates the attack chain to which the attack rule belongs. The method includes: performing intrusion detection on network traffic to determine a first attack rule that the network traffic has hit; the first attack rule is labeled with a target attack chain tag; querying at least one second attack rule labeled with the target attack chain tag from the multiple attack rules; sending the first and second attack rules belonging to the same attack chain to a firewall, so that the firewall performs attack defense according to a protection policy; the protection policy is generated based on the first and second attack rules. The firewall can also perform pre-defense against subsequent attack behaviors based on the attack rules associated with the attack chain, thereby improving the firewall's defense effectiveness.
Owner:BEIJING TOPSEC NETWORK SECURITY TECH +2

A network attack scenario reconstruction method based on device fingerprint in 5G private network scenario

The present invention relates to the technical field of digital information transmission, and in particular to a method for reconstructing a network attack scenario based on device fingerprints in a 5G private network scenario, which includes the following steps: capturing the traffic that triggers the alarm and storing it as a pcap package, generating a list of data packets corresponding to each IP address and traffic; marking the network flow through a five-tuple of <source address, destination address, source port, destination port, timestamp>; extracting the direction and length of the traffic in the network flow as a temporary fingerprint; extracting temporary fingerprints with similar time from a fingerprint database, determining the twin IP, and thus outputting a twin IP list of the attacked IP address; searching for related attack fragments based on the twin IP list, associating multiple attack fragments, and reconstructing the attack scenario. The present invention can associate multiple attack fragments and restore the complete attack scenario without relying on the access rights of the control plane network element, thereby helping analysts to carry out analysis activities such as attack classification and attack prediction.
Owner:POWERCHINA BEIJING ENG CORP

Modeling cyberspace operations and operation effectiveness

A method, system, and computer-readable media for modeling cyberspace operations and the effects thereof. Network and connectivity data for an operational environment model may be retrieved from a network scan. Likelihood data that a network element takes a plurality of possible configurations may be mapped. Determination of a probability of effect of a capability acting on the network element may be based on the likelihood data and uncertainties associated with the capability. Multiple attacks within the operational environment model may be modeled to determine an attack path therethrough. Functional modeling techniques to model functional impacts of attacks on an operational environment model are also disclosed.
Owner:APPLIED RESEARCH ASSOCIATES INC

Attack detection method and device, equipment and storage medium

The invention belongs to the technical field of terminal security, and discloses an attack detection method and device, equipment and a storage medium. According to the method, the process behavior of the target process is matched with the initial detection condition of each preset attack behavior chain; if the initial detection condition is successfully matched with the initial detection condition of any preset attack behavior chain, taking the successfully matched preset attack behavior chain as a target behavior chain; constructing a detection condition list according to the target behavior chain; and if the subsequent process behavior of the target process meets each detection condition in the detection condition list, judging that the high-risk attack is detected. The process behaviors of the processes in the terminal are monitored and matched with the multiple attacks included in the preset attack behavior chains corresponding to the advanced threat programs, so that it is ensured that the terminal can find whether high-risk attacks exist or not in advance, misjudgment of single behavior detection is avoided, and the safety of the terminal is improved. Therefore, the terminal can automatically detect whether the attack exists or not, and the dependence on the server is reduced.
Owner:BEIJING HONGTENG INTELLIGENT TECH CO LTD

A few-shot attack pattern recognition method based on a large language model

The application provides a few-shot attack mode recognition method based on a large language model, comprising: constructing a classification prompt for recognizing a to-be-recognized attack behavior data instance to obtain a coarse classification label; constructing a pseudo-instance generation prompt for generating a pseudo-instance related to the coarse classification label; combining the to-be-recognized attack behavior data instance, the coarse classification label and the pseudo-instance to construct a few-shot reference example; obtaining a fine classification label according to the few-shot reference example; and sorting the fine classification label to obtain a relevance sorting result of an attack mode recognition label and the to-be-recognized attack behavior data instance. The method improves the recognition accuracy of complex and rare attack modes through the construction of a few-shot classification reference example and the recognition of a fine classification label. The method can recognize multiple attack mode recognition labels related to a specific attack behavior from multiple-source heterogeneous attack behavior data, and improves the accuracy and flexibility of attack behavior threat analysis.
Owner:GUANGZHOU UNIVERSITY

Web application firewall vulnerability detection method, device and system based on load variation injection

The invention belongs to the technical field of network security, and particularly relates to a Web application firewall vulnerability detection method based on load variation injection. Comprising the following steps: constructing a unified attack grammar rule base covering multiple attack types; analyzing the original attack load into an abstract syntax tree; carrying out semantic reservation load variation based on the syntax tree to generate a semantic equivalent variation load; performing protection rule detection on the Web application firewall, analyzing a detection result and performing pruning operation on the syntax tree; a Monte Carlo tree search algorithm is utilized, a rule detection mechanism is combined, and a variation path with a high success rate is dynamically evaluated and preferentially tested so as to efficiently generate an antagonistic load capable of bypassing WAF detection; according to the method, the problems of attack failure, low black box test efficiency and insufficient coverage of a single attack type caused by semantic destruction in the prior art are solved, and the WAF rule base vulnerability can be systematically evaluated.
Owner:CHONGQING UNIV OF POSTS & TELECOMM

Bionic multi-weapon fighting robot

The utility model relates to the technical field of fighting robots, and provides a bionic multi-weapon fighting robot which comprises a robot body, walking wheels, a driving mechanism, weapon arms, first motors and attack wheels, the walking wheels are rotationally connected to the robot body, the two first motors are arranged above the front ends of the two weapon arms respectively, and the driving mechanism is connected with the attack wheels. The first motor is in driving connection with the attack wheels, a plurality of oblique teeth are arranged on the circumferences of the attack wheels at intervals, the two attack wheels are located below the front ends of the two weapon arms correspondingly, impact blocks are arranged at the front ends of the weapon arms, the rear ends of the two weapon arms are hinged to the front end of the machine body correspondingly, and the driving mechanism is arranged on the machine body. The driving mechanism is in driving connection with the two weapon arms and used for driving the two weapon arms to be close to and separated from each other. The attack function that clamping attack is carried out through the two weapon arms, grinding or smashing and other damage is carried out through the attack wheel is achieved, the attack diversity is improved, multiple attack actions are carried out at the same time, and the attack effectiveness is also guaranteed.
Owner:HEILONGJIANG XUANSU TECHNOLOGY CO LTD

A voiceprint spoofing defense method, device and computer readable storage medium

PendingCN122372302ASound sourcesDecision model
A method, apparatus, and computer-readable storage medium for voiceprint spoofing defense include: acquiring a speech signal to be verified; extracting multi-dimensional features from the speech signal to obtain a multi-dimensional feature vector, wherein the multi-dimensional feature vector includes at least speech text content features, identity features, sound quality features representing recording or synthesis traces, liveness features representing the physiological characteristics of the sound source, and adversarial perturbation features; fusing the multi-dimensional feature vector to obtain a joint feature vector; inputting the joint feature vector into a pre-trained joint risk decision model to obtain a spoofing risk score; and determining the verification result of the speech signal to be verified based on the comparison result of the spoofing risk score and a preset threshold. This application can effectively detect multiple attack modes such as replay attacks, speech synthesis attacks, and adversarial example attacks simultaneously; and accurately detect high-quality spoofing attacks.
Owner:XIANGYANG DAAN AUTOMOBILE TEST CENT

Accuracy in attack technique labeling in an extended detection system

Techniques for providing a confidence rating for an attack technique tag and a guidance for improving the confidence rating are described. An attack technique analytics engine receives telemetry data, a notification that an attack has been detected using an attack detection source, the notification including an attack technique tag indicating an attack technique used in the attack, and attack technique data including a likelihood of a particular attack technique, from among multiple attack techniques, occurring determined using a particular attack detection source from among multiple attack detection sources. Based on the telemetry, the attack technique tag, and the attack technique data, a confidence rating that the attack corresponds to the attack technique is determined. The attack detection source and attack technique are analyzed to determine a guidance for improving the confidence rating, and the rating and guidance are appended to the attack technique tag.
Owner:CISCO TECHNOLOGY INC

Ammunition for forming aerial barrage

PCT designated stageWO2026176278A1Classical mechanicsPropeller
The ammunition is used on a drone interceptor to combat other drones. The ammunition fires a propeller snare. Ammunition comprises multiple charges with separate electric activation for a multiple attack possibility. The rope forms an air barrier from the moment the shot is fired, it allows the target's propeller to become entangled at a short distance. Twisting the rope increases the likelihood of entanglement on the target. The design of the projectile reduces the likelihood of ricochet. Projectile filled with extra length of rope, it increases the likelihood of entangling the target's propeller. The ammunition is attached to the activation unit. The activation unit is attached to the weapon carrier. The low weight of the weapon allows it to be used on small interceptor drone.
Owner:ZAICEVSKIJ ALEKSEJ

Network monitoring with multiple attack graphs

A computer-implemented method for monitoring a computer network is provided, the method comprising: storing a first attack graph, the attack graph comprising a plurality of nodes each representing an event that may occur within the computer network; storing one or more predetermined variation properties of one or more of the events represented by the nodes, the variation properties being indicative of possible changes to the nodes within the first attack graph; determining a plurality of possible alternative sequences of the nodes in the first attack graph based on the variation properties; generating a plurality of additional attack graphs, each of the additional attack graphs comprising a plurality of the nodes of the first attack graph arranged in one of the possible sequences; and monitoring events within the network to detect a set of events occurring in a sequence that corresponds to one of the additional attack graphs to identify a potential security attack. A computer system including at least one processor and memory storing computer program code configured to perform the said method, and a computer program or computer readable medium comprising instructions that when executed by a computer system cause the computer system to perform the said method are also provided.
Owner:BRITISH TELECOM PLC

Simulated attack data processing method and device, electronic equipment and storage medium

The embodiment of the invention provides a simulation attack data processing method and device, electronic equipment and a storage medium, and the method comprises the steps: firstly, obtaining a simulation attack strategy corresponding to a simulation attack request in response to the simulation attack request of a virtual system; then, based on an attack scene description language, performing stage standardization processing on the simulation attack strategy to obtain multi-stage description data, the multi-stage description data comprising standardized description data of a plurality of attack stages; secondly, on the basis of system parameters of the virtual system, generating a virtual container corresponding to each piece of standardized description data, executing an attack action in each virtual container on the basis of the corresponding standardized description data, and obtaining feedback data in the execution process; and finally, vulnerability data of the virtual system is obtained based on the feedback data, and a risk assessment result of the virtual system is obtained based on the vulnerability data and the feedback data, so that the standard of simulation attack description in the attack and defense drilling process is improved, and the accuracy of attack and defense drilling assessment is improved.
Owner:PENG CHENG LAB

Network security risk identification method and device, storage medium and electronic equipment

The invention discloses a network security risk identification method and device, a storage medium and electronic equipment. Relates to the field of network security detection, and the method comprises the steps: obtaining endogenous threat intelligence data of a to-be-detected network device, the endogenous threat intelligence data comprising risk scores corresponding to a plurality of attack source IPs; multiple pieces of external threat intelligence data are obtained, the multiple pieces of external threat intelligence data are in one-to-one correspondence with the multiple data sources, and the external threat intelligence data comprise original malicious probabilities corresponding to multiple attack source IPs obtained under the corresponding data sources; the original malicious probability represents the probability that the corresponding attack source IP obtained under the corresponding data source is a malicious attack IP; and determining a network security identification result of the to-be-tested network device based on the endogenous threat intelligence data and the plurality of external threat intelligence data. According to the invention, the technical problem of low network security risk identification accuracy in related technologies is solved.
Owner:AGRICULTURAL BANK OF CHINA

A power distribution network black box adversarial sample generation method based on large language model topology reasoning guidance

The application discloses a power distribution network black box confrontation sample generation method based on a large language model topology reasoning guide, which comprises the following steps: determining an attack target of a scheduling task, quantifying a destructive intention of an attacker, and converting a fuzzy attack target into a multi-target attack loss function; using general knowledge and reasoning ability of the large language model, screening out key nodes with the highest attack cost performance, and obtaining a mask vector; under the constraint of the mask vector, generating a specific disturbance vector for a continuous domain or a discrete domain; and performing sample verification. The application introduces a large language model as a topology cognition engine, uses semantic reasoning ability of the large language model to screen out key fragile nodes in a power distribution network, generates an attack mask, and guides a black box optimizer to lock a key subspace through the mask, so that high-quality confrontation samples covering multiple attack targets and action domain types are efficiently generated without accessing an internal structure of the model, and rich robustness training data is provided for intelligent agents.
Owner:XIANGTAN UNIV +1

Decision-making method based on network defense agent

The invention relates to a decision-making method based on a network defense agent, which relates to the field of network security, and comprises the following steps: constructing a network system topological graph based on a connection relationship of network equipment; matching network threats conforming to node attributes on nodes of the network system topological graph by using the generated sigma rule, thereby automatically constructing an attack action space corresponding to any node in the network system topological graph; constructing a plurality of attack agents and defense agents; the intelligent agent comprises a decision network and an evaluation network; the decision network gives an action probability according to the observed local network environment state, and selects an action according to the action probability; the evaluation network evaluates the combined network environment state observed by all the attack agents to obtain the value of a strategy or an execution action; and training an attack agent and a defense agent by utilizing reinforcement learning, and carrying out network defense decision by utilizing the trained defense agent so as to cope with dynamic network attacks.
Owner:JIANGSU RUINING XINCHUANG TECH CO LTD

Liveness detection method and system

The live body detection method and system provided in the specification, after obtaining a target user image of a target user, inputting the target user image into a live body detection model to obtain an attack probability of each attack type in multiple attack types and a clue probability of at least one attack clue corresponding to each attack type, the live body detection model comprising a model obtained after decoupling learning of a feature space according to attack types, and determining a live body detection result of the target user based on the attack probability and the clue probability, and outputting the live body detection result; the scheme can improve the accuracy of live body detection.
Owner:ALIPAY (HANGZHOU) INFORMATION TECH CO LTD

Security defense method, system and device for controller area network bus and medium

The embodiment of the invention provides a security defense method, system and equipment for a controller area network bus, and a medium, and belongs to the field of communication security of the controller area network bus. The method comprises the following steps: collecting bus communication behavior data through a trusted monitoring node; the method comprises the following steps: acquiring a pre-shared key, constructing a network security threat knowledge graph based on the pre-shared key, generating a dynamic inter-frame interval sequence for each message ID to be sent on a bus based on the pre-shared key and a pseudo-random function, and adjusting at least one defense parameter according to a potential attack path output by the knowledge graph; before a sending node is controlled to send messages, a credible monitoring node calculates legal sending time windows of all the messages based on the same dynamic inter-frame interval sequence; and controlling the trusted monitoring node to monitor the bus, and if the occurrence time of the start bit of the message is detected to be earlier than the legal sending time window, judging that the time sequence is illegal. Microsecond-level real-time active defense covering multiple attack types is achieved, and meanwhile the real-time performance of key messages is guaranteed through dynamic scheduling.
Owner:SINO TRUK JINAN POWER CO LTD

Data-encrypted anti-attack method and system for accessing electric vehicle to power distribution network

The invention discloses a data-encrypted anti-attack method and system for accessing an electric vehicle to a power distribution network. Constructing an attacked behavior model of the charging station system by adopting a Markov decision process; the method comprises the following steps: firstly, defining and collecting intrusible units in a charging station system, finding out an initial access point, starting from the initial access point, traversing all the intrusible units based on a state set and an action set, and generating a plurality of attack paths to form an attack path tree; then, calculating an optimal path and a state value function matrix through a Markov decision process; and training a neural network through the historical state value function matrix, and finally outputting the attacked probability of the charging station system by the neural network so as to judge whether the charging station system is attacked or not. After training is completed, real-time data of a charging station system are obtained, and occurrence of network attacks is judged through first-level threshold early warning and second-level intelligent detection. According to the invention, the network security of the electric vehicle accessing the power distribution network can be effectively improved, and potential attacks can be identified and defended in time.
Owner:STATE GRID LIAONING ELECTRIC POWER CO LTD +2

A Method for Generating Optimal Attack Strategies for Wind Farms Considering DoS and FDIA

This application relates to a method for generating optimal attack strategies for wind farms considering DoS and FDIA attacks. The method includes: first, establishing an optimized control model and an optimal scheduling model for normal operation of the wind turbine; then, constructing an FDIA control command tampering attack model, a DoS attack model, and an FDIA wind speed measurement tampering attack model, respectively; and finally, combining wind turbine operation constraints and attack resource constraints to solve for the attack strategy that maximizes the total power output loss of the wind farm and complete a quantitative assessment of the attack impact. This invention integrates DoS and FDIA attacks into the physical operation constraint framework of the wind turbine, generating an implementable optimal attack strategy with the goal of maximizing power output loss, achieving unified quantitative assessment of multiple attack scenarios, and providing support for the network security risk analysis and protection of wind farms.
Owner:STATE GRID ANHUI ELECTRIC POWER CO LTD ELECTRIC POWER SCI RES INST

AI-driven missile defense system

We provide a missile defense system that utilizes generative AI to perform real-time dynamic analysis and generate defensive measures, thereby improving the responsiveness and flexibility of missile defense. [Solution] This invention provides a missile defense system that utilizes generative AI and ensemble learning with multiple AI models to analyze enemy missile flight data and communication signals in real time and immediately generate jamming signals and interception measures. Through ensemble learning, each AI model analyzes the threat from its own perspective, and the generative AI integrally generates the optimal defense measures. Furthermore, the continuous learning function improves the accuracy of defenses in subsequent instances, and enhances responsiveness and flexibility against irregular threats and multiple attacks. This system dramatically strengthens the ability to defend against diverse attacks.
Owner:中村义一

Accuracy in attack technique labeling in an extended detection system

Techniques for providing a confidence rating for an attack technique tag and a guidance for improving the confidence rating are described. An attack technique analytics engine receives telemetry data, a notification that an attack has been detected using an attack detection source, the notification including an attack technique tag indicating an attack technique used in the attack, and attack technique data including a likelihood of a particular attack technique, from among multiple attack techniques, occurring determined using a particular attack detection source from among multiple attack detection sources. Based on the telemetry, the attack technique tag, and the attack technique data, a confidence rating that the attack corresponds to the attack technique is determined. The attack detection source and attack technique are analyzed to determine a guidance for improving the confidence rating, and the rating and guidance are appended to the attack technique tag.
Owner:CISCO TECHNOLOGY INC

An extensible artificial intelligence attack benchmarking method and system

ActiveCN117312119BResolve the model under testSolve the problem of language restrictionsData setAlgorithm
This invention provides an scalable AI attack benchmark testing method and system. A model conversion module transforms the tested model according to its type and framework, obtaining a converted model that matches the attack framework. The dataset attacks the converted model, yielding a test result. The attack framework invokes various attack algorithms with a standardized format, generates corresponding attack scripts, and then performs several attacks on the converted model, resulting in multiple attack results. When testing the next tested model, the model conversion module again transforms its framework according to its type before launching the attack. The advantages are: it can flexibly convert for different AI models, attacking the converted model to obtain attack results, without needing to rebuild test modules for different AI models, improving attack efficiency, reducing testing costs, and solving the problem of existing testing methods (frameworks) being limited by the tested model and language.
Owner:北京银联金卡科技有限公司

Network attack path diagram generation method and electronic equipment

The invention provides a network attack path diagram generation method and electronic equipment, and the method comprises the steps: receiving a plurality of pieces of attack event data comprising source IP addresses and target IP addresses, and carrying out the generation of a network attack path diagram for each piece of target attack event data in a target data group with the same target IP address and the same source IP address, calculating the curvature radius of the target attack event data based on the index numbers and the correction numbers corresponding to all the target attack event data, the first initial coordinate corresponding to the source IP address and the second initial coordinate corresponding to the target IP address; generating an attack path corresponding to the target attack event data based on the curvature radius, the first initial coordinate and the second initial coordinate; by generating the attack paths with different curvatures for the multiple attack events between the same source IP address and the same target IP address, the problems of path overlapping and poor readability are avoided, clear visualization of the attack paths is realized, and the analysis efficiency and accuracy are improved.
Owner:CHINA TELECOM NETWORK SECURITY TECH CO LTD

Filter updating method and device, equipment, medium and product

The embodiment of the invention provides a filter updating method and device, equipment, a medium and a product, and relates to the technical field of artificial intelligence. According to the method, diversified mixed samples are generated through disturbance, an adversarial experience library of a filter is expanded, the ability of recognizing multiple attack modes is established in the initial stage, a robustness foundation is laid for coping with dynamic attacks, and then target domain scene data are introduced, so that the robustness of the filter is improved. The information divergence between a mixed sample and a target domain sample is calculated in real time, the environment change degree is accurately quantified, parameter updating is automatically triggered in a real environment, the limitation that a traditional method depends on static rules and fixed period updating is broken through, the rapid response and continuous defense capability to novel threats is achieved, and the method is suitable for popularization and application. And the updating efficiency of the filter is improved.
Owner:CHONGQING NORMAL UNIVERSITY +2