Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

1253 results about "Network attack" patented technology

System and Method for Improving Cybersecurity of a Network

A system and method for mitigating cyber-attacks against a target network comprising interconnected note that is implemented by Open Systems Interconnection (OSI) layers monitors the target network for detecting vulnerabilities across one or more OIS layers. a virtual network comprising a virtualized representation of the target network where the virtual network includes one or more virtual nodes that are annotated with identified vulnerabilities of one or more corresponding nods of the target network. A reference database can be configured to store records of known cyber-attacks and their corresponding mitigations where cyber-attacks on the virtual network are simulated based on records of known cyber-attacks and successful cyber-attacks. An AI engine can be configured to generate one or more mitigation actions based on simulation of the cyber-attacks before implementing the one or more mitigation actions to the target network.
Owner:THE GOVERNMENT OF THE UNITED STATES OF AMERICA AS REPRESENTED BY THE SEC OF HOMELAND SECURITY

Network attack tracing method and device based on threat graph, equipment and medium

The invention relates to a network attack tracing method and device based on a threat graph, equipment and a medium. The method comprises the steps of obtaining network security log data from multiple security data sources, and performing standardization processing to obtain a structured network security event data set; extracting threat entities and behavior relationships among the threat entities from the structured network security event data set to obtain an entity set and a relationship set; constructing a threat map according to the entity set and the relationship set, and performing time data slicing according to the timestamp to obtain a map snapshot and map metadata; based on a predefined attack chain template, identifying an attack chain sub-graph conforming to an attack behavior structure in the threat graph to obtain an attack chain set and a path reachability matrix; and according to the attack chain set and the path reachability matrix, attack path inversion is carried out by taking the target node as an end point, and an attack traceability path and a graph evolution process display result are obtained. By adopting the method, the network attack path can be identified and the attack source can be traced.
Owner:白宗鑫

Network attack detection method and system based on distributed intelligent probe

The invention provides a network attack detection method and system based on a distributed intelligent probe, and the method comprises the steps: receiving real-time flow data synchronously collected by the distributed intelligent probe at each node of a network, carrying out the inter-node interaction relation modeling processing of the real-time flow data, recognizing a flow communication mode between different network nodes, and carrying out the detection of the network attack. Generating a flow association map containing the node connection relationship and the communication frequency; carrying out abnormal communication path mining based on the flow association map, and extracting a node communication sequence with an abnormal mode by analyzing the deviation degree of a node connection relationship and the fluctuation characteristics of communication frequency; performing pattern matching processing on the node communication sequence and an attack behavior template in a preset attack feature library, calculating sequence matching similarity and generating an attack matching degree score set; and determining a network attack type and attack source node positioning information, and generating a network attack detection result. According to the invention, the practicability and effectiveness of network attack detection are improved.
Owner:SHENZHEN XIYUE ZHIHUI DATA CO LTD

Intelligent network attack surface prediction method and system based on deep learning

The invention relates to an intelligent network attack surface prediction method and system based on deep learning, and belongs to the technical field of network security and information, and the method comprises the steps: obtaining network asset information, vulnerability distribution information and external threat intelligence data in a target network environment, and carrying out the preprocessing to generate a standardized data set; inputting the standardized data set into a pre-trained deep learning model to extract a feature vector related to the network attack; reasoning and analyzing a potential attack link based on the feature vector and the knowledge graph, and combining an association relationship among a network asset node, a vulnerability node and a threat intelligence node in the knowledge graph; and finally, according to a reasoning analysis result, evaluating an intrusion path possibly utilized by an attacker, outputting an attack surface prediction result, and presenting the attack surface prediction result in the form of an attack path list. According to the scheme, a potential attack link can be subjected to deep reasoning analysis, an intrusion path possibly utilized by an attacker can be accurately predicted, and the effectiveness of network security protection is improved.
Owner:BEIJING HUAYUNAN INFORMATION TECH CO LTD

Security protection method and apparatus for customer service management system

PCT designated stageWO2025222719A1Securing communicationData setData access
The present invention relates to the technical field of network security protection. Disclosed are a security protection method and apparatus for a customer service management system. The method comprises: acquiring an employee data set, and performing permission assignment, so as to generate an employee operation permission set; performing identity verification on an access user, and determining a data management operation permission range of the access user; acquiring a sensitive data set for encryption processing, and storing same in a customer service management system; accessing data of the customer service management system, implementing an access control policy, and performing risk assessment, so as to generate a system risk level; extracting detected anomalous data, synchronizing same to a security protection network, and outputting a protection control policy; and executing the protection control policy for security assessment, regularly updating the protection control policy, and performing intelligent security protection on the customer service management system. The present invention solves the technical problem in the prior art that customer service management systems have low security protection capacity, which leads to difficulty in preventing network attacks, thus achieving the technical effect of improving the security protection capacity of customer service management systems.
Owner:SHANGHAI HANDPAL INFORMATION TECHNOLOGY SERVICE CO LTD

Method and device for constructing network attack behavior chain and active defense, and computer equipment

The invention belongs to the technical field of network security, and relates to a network attack behavior chain construction and active defense method and device and computer equipment, and the method comprises the steps: collecting full-flow data and a multi-source log from a network environment, and carrying out the preprocessing of the full-flow data and the multi-source log; storing the preprocessed full-flow data and multi-source logs, and establishing an associated index; through a deep learning algorithm and an unsupervised model, abnormal traffic and attack behaviors are identified from the full-traffic data and the multi-source logs; reconstructing the fragmented attack events into a complete behavior chain through a graph neural network and a visualization mode; based on the AI model, a dynamic defense strategy is generated, and a response action is automatically executed; through time sequence prediction and a deep learning model, a future attack trend is predicted, and active defense is realized. The method improves the unknown attack detection capability, optimizes the traceability efficiency, enhances the defense initiative, guarantees the real-time performance and accuracy of network attack prediction, and has compliance adaptability.
Owner:SHENZHEN Y& D ELECTRONICS CO LTD

Network security event tracing method, system and device based on AI and medium

The invention discloses an AI-based network security event tracing method, system and device and a medium, and the method specifically comprises the steps: constructing a network entity association graph based on a multi-modal data set, mining the implicit association between entities through a graph convolutional network, recognizing an APT attack chain, and obtaining graph feature data; based on the multi-modal data set, an LSTM-Transform hybrid model is adopted to analyze time sequence characteristics of network traffic, slow penetration and low-frequency detection behaviors are detected, and time sequence characteristic data are obtained; based on the graph feature data and the time sequence feature data, high-value features are screened through a genetic algorithm, and cross-modal combination features are generated by using a depth auto-encoder; based on cross-modal combination features, a network environment digital twin is constructed, an attack diffusion path is simulated, and a service influence range is quantified. According to the method, accurate tracing of the network security event is realized, and the detection and tracking capabilities of complex network attacks and the intelligent level of a response strategy are comprehensively improved.
Owner:ANHUI SANQI JIYU NETWORK TECH CO LTD

Active defense system and method based on multi-protocol dynamic simulation and distributed trapping

The invention provides an active defense system and method based on multi-protocol dynamic simulation and distributed trapping. The active defense method based on multi-protocol dynamic simulation and distributed trapping comprises the following sub-steps: S1, constructing a multi-protocol dynamic simulation environment; s2, deploying distributed trapping nodes; s3, deep trapping of attack behaviors; s4, attack chain reconstruction and behavior analysis; s5, performing adaptive confusion and adversarial enhancement; s6, automatic threat intelligence production and feedback; by loading the protocol template library and initializing the state machine, the response can be dynamically generated according to the real-time session context, and dynamic simulation of various service protocols is adopted, so that the detection capability on network attacks is improved, potential threats can be captured more quickly, and the risks of missing report and false report are reduced; and through an automatic threat intelligence generation and feedback mechanism, in combination with IOC index identification, structured output and real-time response, a defense strategy can be quickly responded and adjusted.
Owner:CHINA LIFE INSURANCE CO LTD

Information physical security defense method, system and equipment based on distribution network digital twin simulation platform, and medium

The invention discloses an information physical security defense method, system and device based on a distribution network digital twin simulation platform and a medium, and belongs to the technical field of information security and control defense of the power distribution Internet of Things, and the method comprises the steps: constructing a three-dimensional channel for interaction of a physical power grid, an information model and simulation data; on the basis of a three-dimensional channel, a three-state dynamic conversion model among a steady state, a transient state and a recovery state is constructed, and multi-state automatic switching simulation is achieved through sub-region division and parallel computing; a multi-level risk modeling system oriented to various risks is constructed based on simulation results, complex attack scenes are identified, and mapping of risk types and response paths is achieved; security risk assessment and defense strategy generation verification are completed, and intelligent collaboration and continuous learning of cross-domain defense strategies are achieved through collaborative optimization. According to the method, the construction efficiency of a complex risk scene is improved, quantitative analysis of cross-domain risks such as circuit breaker mis-tripping caused by network attacks is realized, and the limitation of traditional single-domain risk analysis is broken through.
Owner:GUIZHOU POWER GRID CO LTD

Intelligent automobile cooperative cruise safety control method under Dos attack and physical fault

The invention discloses an intelligent automobile cooperative cruise safety control method under Dos attacks and physical faults, and relates to automobile intelligent safety and automatic driving. A hierarchical control framework is adopted and comprises an observer layer and a tracking layer. The method comprises the following steps: establishing a vehicle longitudinal dynamics model and a DoS attack model for DoS attack in a V2X communication network and the problems of sensor and actuator faults and parameter isomerism of a vehicle; a completely distributed self-adaptive preset time observer based on event triggering is designed for each following vehicle in the observer layer, and rapid and accurate estimation of the state of the pilot vehicle is achieved; the method comprises the following steps: constructing an augmentation system at a tracking layer, designing a distributed intermediate observer, carrying out online estimation and compensation on faults of a sensor and an actuator, designing a distributed active fault-tolerant controller based on a fault estimation value and a pilot vehicle state estimation value, and calculating a wheel driving torque to realize safe cruise control. Multiple threats of coexistence of network attacks and physical faults are effectively handled, and the stability and safety of the cooperative cruise system are ensured.
Owner:XIAMEN UNIV

Edge device network threat detection method and system based on large electric power model

The invention relates to the technical field of network security, and particularly discloses an edge device network threat detection method and system based on an electric power large model, and the method comprises the steps: capturing a network message sequence in real time, extracting a time sequence randomness feature and a semantic deviation feature from a time dimension and a protocol dimension, and carrying out the fusion to form a comprehensive threat feature vector; performing multi-dimensional feature analysis and time sequence modeling by adopting a lightweight electric power large model to realize millisecond-level threat assessment; establishing a multi-level response mechanism, dynamically triggering a differential protection strategy according to the threat level, and ensuring the reliability and consistency of response actions through digital signature and collaborative verification; according to the method, the complex network attack in the power edge equipment can be effectively identified, the threat detection accuracy and the system defense capability are improved, and the strict requirements of a power system on real-time performance and reliability are met.
Owner:STATE GRID JIANGXI ELECTRIC POWER CO LTD RES INST +1

Network attack active defense strategy optimization method based on deep reinforcement learning

The invention discloses a network attack active defense strategy optimization method based on deep reinforcement learning, and the method comprises the following steps: collecting multi-source data of a network environment, and carrying out the feature clipping and white list feature reservation; performing normalization and coding processing to generate a security situation vector; constructing a multi-index reward function, and generating an instant reward value and an event-level reward value; executing a double-closed-loop mechanism through an improved PPO model, and respectively outputting an instant strategy instruction and a long-term strategy parameter; performing multi-source evidence commissioning on the instant strategy instruction and the security situation vector, and judging a key evidence loss condition to obtain an execution token; inputting a risk budget pool to carry out resource quota checking, and executing anti-jitter and cooling control; and optimizing parameters of the multi-index reward function through a causal account book. According to the method, rapid response and continuous optimization of various attack behaviors can be realized, the defense effect and the resource utilization rate are considered, the false report and missing report rate is reduced, and the self-adaptability and stability of a network defense system are improved.
Owner:QIAN XINGCHENG NETWORK SECURITY TECH (HUNAN) CO LTD

Power distribution network protection resource dynamic allocation method, system and device and storage medium

The invention discloses a power distribution network protection resource dynamic allocation method, system and device and a storage medium, and relates to the field of power system network security protection, and the method comprises the steps: collecting the operation data of a power distribution network in real time, constructing a multi-dimensional fusion data set, and predicting a potential attack path through an attack path prediction model in combination with a historical attack mode library; performing risk assessment on the predicted potential attack path, and calculating the protection resource demand quantity of each region of the power distribution network in combination with the topological structure of the power distribution network and the importance of key nodes; according to a risk assessment result, dynamic allocation and real-time scheduling of protection resources are realized in combination with a resource constraint condition; the method can grasp the operation of the power distribution network in real time, accurately predict the potential attack path, accurately evaluate the risk and calculate the protection resource demand. Dynamic allocation and real-time scheduling of protection resources are realized, the resources are reasonably utilized, the cost is reduced, the protection effect is improved, and safe and stable operation of the power distribution network under complex network attacks is ensured.
Owner:GUIZHOU POWER GRID CO LTD

Power network attack chain dynamic deduction and intelligent response process method, system and device based on deep reinforcement learning, and medium

The invention discloses a power network attack chain dynamic deduction and intelligent response process method, system and device based on deep reinforcement learning and a medium, and belongs to the technical field of network security and power system protection. Multi-modal data is aligned and normalized, an event view cache is constructed, and the generalization detection capability on process camouflage and memory injection attacks is improved through a federated learning collaborative detection mechanism; based on the event view cache and historical threat intelligence, generating a dynamic attack knowledge graph, constructing a deep reinforcement learning model taking the attack knowledge graph as an environment, calculating an attack influence index by using a Bayesian network, and generating a differentiated security response instruction; and realizing attack path backtracking and attack source positioning based on the attack knowledge graph. According to the method, multi-modal data fusion analysis and strategy adaptive updating are realized, and the attack chain identification accuracy and evidence chain construction integrity are remarkably improved.
Owner:GUANGXI POWER GRID CORP

Network evidence obtaining and attack chain reconstruction method based on threat alarm

PendingCN120915528ASecuring communicationShardNetwork forensics
The invention discloses a network evidence obtaining and attack chain reconstruction method based on threat alarm, and belongs to the field of network security. Aiming at the problems of massive alarm fragmentation, strong attack chain concealment, low evidence obtaining efficiency and the like existing in a traditional network evidence obtaining method, the invention provides a dynamic reconstruction model of multi-dimensional alarm aggregation and probabilistic reasoning. Threat alarms are aggregated through an improved DBSCAN algorithm, an attack behavior graph is constructed, and attack chain probabilistic reasoning is carried out in combination with a time sequence Petr i network and an HMM. Experiments prove that the alarm aggregation compression rate reaches 92.3%, the attack chain reconstruction accuracy rate reaches 88.6%, the time consumed by single analysis is less than 3 seconds, and the network attack tracing and evidence obtaining efficiency is effectively improved.
Owner:GUANGXI POWER GRID CORP

Heterogeneous atlas-based network attack path prediction method and device, and medium

The invention discloses a heterogeneous atlas-based network attack path prediction method and device and a medium, and relates to the technical field of network security, and the method comprises the following steps: collecting multi-source heterogeneous data, extracting basic entities and relationships to generate structured data, defining nodes and relationship types by using a TPP framework, and generating a real-time heterogeneous atlas by using a dynamic update mechanism; based on the real-time dynamic heterogeneous atlas and the multi-source heterogeneous data, generating an attack association feature matrix, extracting potential threat features through feature fusion, mining attack association paths, and generating an attack path candidate set; constructing a quantum field game model based on the attack path candidate set, generating an evasion path set in combination with a quantum tunneling effect, quickly adapting to attacks through dual variational optimization, and generating a final attack path prediction result and a confidence score; according to the method, the game confrontation model is constructed through the attack path candidate set, and the optimal defense strategy can be quickly found in the face of continuously changing attack modes.
Owner:JIANGSU ELECTRIC POWER INFORMATION TECH

Network attack cross-platform collaborative protection processing method and device

The invention discloses a network attack cross-platform collaborative protection processing method and device, and relates to the technical field of network security. The method comprises the following steps: each heterogeneous security device captures security log data in real time, converts the security log data into an uplink protocol message containing security event semantic description, and sends the uplink protocol message to a central server; analyzing and reasoning the uplink protocol message through a built-in large language model to construct an attack chain of a network attack behavior, generating a downlink protocol message containing an action intention based on the attack chain and a preset disposal strategy library, and sending the downlink protocol message to the target heterogeneous security device; and the target heterogeneous security equipment converts the downlink protocol message into an operation instruction which can be executed by the target heterogeneous security equipment through a built-in translation engine. According to the method, different types of safety equipment logs and instructions are converted into unified semantic information which can be understood by a machine in the interaction process, and real-time association, intention recognition and automatic two-way cooperation of safety events are achieved.
Owner:BEIJING CHAITIN TECH CO LTD

Computer-implemented system and method for cybersecurity threat analysis using federated machine learning and hierarchical task networks

ActiveUS12500920B2Machine learningSecuring communicationHierarchical task networkInternet traffic
A system and method for cyber exploitation path analysis and response using federated networks to minimize network exposure and maximize network resilience, with the ability to simulate complex and large scale network traffic through the use of federated training networks, by gathering network entity information, establishing baseline behaviors for each entity, and monitoring each entity for behavioral anomalies that might indicate cybersecurity concerns. Further, the system and method involve incorporating network topology information into the analysis by generating a model of the network, annotating the model with risk and criticality information for each entity in the model and with a vulnerability level between entities, and using the model to evaluate cybersecurity risks to the network. Lastly, network attack path analysis and automated task planning for minimizing network exposure and maximizing resiliency is performed with machine learning, generative adversarial networks, hierarchical task networks, and Monte Carlo search trees.
Owner:QOMPLX INC

Network attack-oriented cluster area coverage collaborative search path planning method

The invention relates to a network attack-oriented cluster area coverage collaborative search path planning method, which comprises the following steps of: regarding each unmanned aerial vehicle as a node, iteratively updating a state value, and modeling an unknown task area which needs to be subjected to coverage search; the node state values are sorted and compared, and normal neighbor node state values are reserved and updated; an adaptive MSR algorithm and an MPC-PSO-based path planning method are fused through a communication topology robustness constraint condition to form an anti-attack closed-loop control framework, and an optimal path decision at the current moment is made; according to the method, the relation between the number of neighbor nodes and communication topology robustness is found, and in multi-objective optimization of path planning, the lower limit of the number of the neighbor nodes serves as a hard constraint and is directly associated to a return function. The problems of how to defend network attacks and how to overcome path optimization and coverage search robustness insufficiency of the unmanned aerial vehicle cluster are solved, and it is ensured that state consistency and stable cooperative control can still be achieved when the unmanned aerial vehicle cluster is subjected to the network attacks.
Owner:EAST CHINA INST OF COMPUTING TECH +1

Computer network security data processing method and system based on artificial intelligence

The invention discloses a computer network security data processing method and system based on artificial intelligence, and the method comprises the steps: building a multi-channel deep learning fusion model, extracting spatial local features in a traffic sequence through employing a 1D-CNN one-dimensional convolutional neural network, capturing a long-range time sequence dependence relation between log events, and carrying out the recognition of the long-range time sequence dependence relation between log events; modeling the user operation behavior sequence based on an LSTM (Long Short-Term Memory) network, and fusing the feature weight by using an attention mechanism to obtain a fused feature vector; inputting the fusion feature vector into a classifier established based on an OS-ELM online sequence extreme learning machine to perform real-time threat assessment, and outputting a probability index of network attacks occurring in a short time in the future; and generating a cooperative defense decision according to the network attack probability index, and sending the cooperative defense decision to security equipment for execution. Excessive defense or insufficient protection is avoided, and the cooperation efficiency of safety equipment is remarkably improved.
Owner:SHANDONG CHRISTIE CULTURAL IND CO LTD

Network security protection system and method based on electric power emergency communication environment

The invention belongs to the technical field of network security, and particularly relates to a network security protection system and method based on an electric power emergency communication environment, and the system comprises a quantum-classical hybrid encryption system which is used for generating a dynamic key in real time; the biological characteristic driven dynamic trust ring is used for equipment identity authentication; the unmanned aerial vehicle relay network protocol is used for data transmission; the secret key after-reading burn-down protocol is used for information secret key after-reading burn-down; a key output by the quantum-classical hybrid encryption system is used for authentication encryption of a biological characteristic driven dynamic trust ring, an unmanned aerial vehicle relay network protocol transmits data encrypted by the quantum key, and a key burn-down protocol is used for reading encrypted data to trigger a key burn-down mechanism. According to the method, the key security is improved, the network attack difficulty is increased, the communication delay in a disaster is reduced, man-in-the-middle capture and attack can be immunized, and the problem of contradiction between the encryption strength and the real-time performance is solved.
Owner:CHINA SOUTHERN POWER GRID COMPANY

Network attack identification method and device based on heterogeneous graph neural network

The embodiment of the invention provides a network attack identification method and device based on a heterogeneous graph neural network, and relates to the technical field of network security and heterogeneous graph self-supervised learning methods. The method comprises the following steps: acquiring different types of security data from a security log source, and extracting security entities and association relationships from the security data to construct a heterogeneous graph; extracting behavior embedding vectors of various nodes from the heterogeneous graph through a self-supervised learning mechanism; and analyzing the behavior embedding vector by using a preset algorithm to identify potential suspicious users, malicious hosts and network attack entry points. According to the method and the device, the problem that network attacks are difficult to identify for multi-source heterogeneous complex behaviors based on a modeling mode in the prior art is solved, and the effect of improving the intelligence and automation level of safety monitoring is achieved.
Owner:CHINA EVERBRIGHT BANK

Intelligent prioritization of assessment and remediation of common vulnerabilities and exposures for network nodes

The node exposure score generator and the attack path modeling component are configured to cooperate to analyze the actual detected vulnerabilities that exist for that network node in the network, the importance of network nodes in the network compared to other network nodes in the network, and the key pathways within the network and the vulnerable network nodes in the network that a cyber-attack would use during the cyber-attack in order to provide an intelligent prioritization of remediation actions to remediate the actual detected vulnerabilities for each network node from the network protected by a cyber security appliance.
Owner:DARKTRACE HLDG LTD

Railway communication network early warning method and system based on intrusion detection

The invention provides a railway communication network early warning method and system based on intrusion detection, and the method comprises the steps: collecting the protocol session flow of a key node of a railway communication network, and carrying out the analysis to obtain session-level interaction data; extracting a time sequence feature and a state conversion feature of the protocol session, calculating a dynamic information entropy value, and generating an entropy feature vector; constructing a behavior chain sequence of the equipment, and calculating a behavior chain probability by adopting an attenuation weighted N-Gram model; dividing network operation scenes through time-sensitive clustering, and establishing a dynamic baseline library for storing entropy threshold baselines and behavior chain probability threshold baselines of the scenes; entropy deviation detection and behavior chain anomaly detection are executed in parallel; and when the entropy deviation detection and the behavior chain anomaly detection trigger alarms at the same time, generating a high-confidence alarm and linking the protection equipment. According to the method, through a dual detection mechanism of dynamic information entropy analysis and an attenuation weighting behavior chain, and in combination with time-sensitive scene clustering, high-precision low-false-alarm early warning of complex railway communication network attacks is realized.
Owner:BEIJING GUOTIE HUACHEN COMM TECH CO LTD

Network security situation awareness method and system

The invention relates to the technical field of network security monitoring, and discloses a network security situation awareness method and system, and the method comprises the steps: collecting a multi-source heterogeneous log, carrying out the standardized analysis, and obtaining log event data; performing real-time analysis by utilizing a dynamic baseline association engine based on the log event data to obtain log association alarm data, analyzing a triple from the log association alarm data, constructing a basic knowledge graph based on the triple, performing rule reasoning and embedded reasoning, and integrating reasoning results to form a situation-enhanced security situation knowledge graph; threat data are extracted according to the security situation knowledge graph, the threat data are optimized in combination with a graph neural network GAT to obtain a final network attack threat value, network security situation awareness is carried out based on the network attack threat value, and the threat data comprise comprehensive criticality and an attack influence range. According to the invention, the efficiency and effect of network security management can be improved.
Owner:TONGFANG KNOWLEDGE DIGITAL PUBLISHING TECH CO LTD

Dynamic event trigger fault detection method under DoS network attack

The invention relates to the technical field of network detection, and provides a dynamic event trigger fault detection method under DoS network attack, which comprises the following steps: establishing a linear state space model of a network control system; defining a non-attack interval and an attack interval of system operation, and constraining attack frequency and duration; the observer gain is switched according to the current non-attack interval or attack interval of the system; a dynamic event triggering mechanism is constructed, and the triggering condition depends on the output state and the internal dynamic variable of the full-order switching observer and is used for dynamically adjusting the data transmission frequency; establishing a closed-loop switching system model; and analyzing system index stability according to the closed-loop switching system model, and cooperatively designing observer gain, controller gain and event triggering parameters. According to the invention, through quantification of the DoS attack model, the dynamic event triggering mechanism and collaborative optimization design, the effects of effectively detecting the system fault and improving the utilization rate of the network channel are achieved.
Owner:GUANGZHOU UNIVERSITY

Multi-protocol integration method and device, equipment, storage medium and program product

The invention relates to a multi-protocol integration method and device, equipment, a storage medium and a program product, which are applied to a bastion host, and the bastion host comprises a communication port. The method comprises the following steps: firstly, receiving a first access request generated based on a first protocol and sent by each client through a communication port, then, determining target equipment needing to be accessed by each client according to the first access request, then, determining a second protocol supported by each target equipment based on preset configuration of each target equipment, and finally, sending the second protocol to the client through the communication port. And converting each first access request based on the first protocol and the second protocol, determining a second access request of each client, and accessing the corresponding target device through the second access request. By adopting the method, the number of communication ports can be reduced, so that the network attack surface is reduced, potential security holes and threats are reduced, and the access security of the target equipment is improved.
Owner:CHINA TELECOM CLOUD TECH CO LTD

Power distribution network reconstruction method and device based on Stackelberg game

The invention discloses a power distribution network reconstruction method and device based on the Stackelberg game, and belongs to the technical field of electric power systems, and the reconstruction method comprises the steps: modeling the attack and defense confrontation of an attacker and a defender as the Stackelberg game, taking the attacker as a leader, the defender as a follower, and taking network reconstruction as a defense means; a blog framework is provided for formulating an optimal defense means; and fusing the game framework and a mixed integer linear programming algorithm, and calculating an optimal defense means of the defender by solving a Stackelberg equilibrium point. According to the method, the optimal defense scheme for coping with a strategic attacker can be calculated, and the uncertainty of attack positioning is considered in decision making, so that the minimum system reconstruction cost is realized while the voltage safety of the power grid is ensured, and the safety and the toughness of the power distribution network under network attacks are effectively improved.
Owner:NANJING UNIV OF POSTS & TELECOMM

Unified communication system

PendingCN120935246ATransmissionService developmentHealth check
According to the unified communication system provided by the invention, the stable communication connection between the client and the platform is realized through the end-side SDK module, the underlying protocol difference is shielded, and the complexity of multi-protocol adaptation is reduced. The registration center module and the service discovery middleware work cooperatively to perform automatic registration and health check on the service instance, so that the health state of the routing target node is ensured, the request is prevented from being distributed to the fault instance, and the reliability of the system is improved. The load balancing service module serves as a unified communication entrance, processes all flows in a centralized manner, reduces the number of externally exposed ports of the system, shrinks a network attack surface, and enhances security. The platform SDK module provides an interactive interface for the service platform, so that the service platform does not need to care about complex communication details, and the service development efficiency and the system maintainability are improved. The management service web platform provides a centralized visual management and control interface for all the modules, convenient management of plug-ins, SDKs and system configuration is achieved, and the operation and maintenance difficulty is reduced.
Owner:SUZHOU MAXNET NETWORK SECURITY TECH CO LTD

Computer network security intelligent monitoring method and system based on behavior analysis

The invention provides a computer network security intelligent monitoring method and system based on behavior analysis, relates to the field of network security monitoring, and solves the technical problems of low network security monitoring accuracy and difficulty in mining deep association between behavior events in the prior art. The method comprises the following steps: collecting behavior event data of a plurality of entities in a network and coding to obtain a spatio-temporal context coding vector; based on the spatio-temporal context coding vector, constructing a spatio-temporal causal graph by using a causal discovery algorithm; on the basis of a space-time causal graph, performing anomaly detection by using the graph neural network model subjected to antagonism training, and identifying an abnormal causal path in the graph; and carrying out risk propagation simulation on the abnormal causal path to restore a complete attack chain to obtain a network attack chain. The method and device are used in the computer network security intelligent monitoring process.
Owner:LOUDI CAREER COLLEGE