Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

1720 results about "Network attack" patented technology

Network attack dynamic detection and security protection method and system based on artificial intelligence

The invention relates to the technical field of network attacks, in particular to a network attack dynamic detection and security protection method and system based on artificial intelligence, and the method comprises the following steps: S1, data collection: collecting a multi-protocol communication data flow of network equipment, and generating a multi-dimensional feature vector; s2, constructing a cross-protocol behavior graph: generating a dynamically updated network behavior graph; s3, anomaly detection: identifying an abnormal behavior mode through the deep residual sequential network, and outputting threat evaluation parameters; s4, protection strategy generation: generating a dynamic protection instruction set through a reinforcement learning decision algorithm; and S5, protection execution: executing the dynamic protection instruction set to complete safety protection operation. According to the method, the multi-protocol fusion behavior graph is constructed, and an abnormal detection mechanism of graph nerve and differential modeling and a dynamic response strategy driven by reinforcement learning are introduced, so that high-precision identification and efficient protection of network attacks are realized.
Owner:TIBET LANGJIE INFORMATION TECH CO LTD

Artificial intelligence network security system based on multi-modal large model training

The invention relates to the technical field of intelligent security operation and maintenance, in particular to an artificial intelligence network security system based on multi-modal large model training, which comprises a server fault diagnosis module, a network attack detection module, an endpoint security monitoring module, a key management optimization module and a threat analysis feedback module. According to the method, the fault prediction accuracy is improved through multi-dimensional data analysis, service interruption caused by sudden hardware faults is reduced, the network access frequency, source and instruction features are evaluated based on the server abnormality, the attack detection accuracy is improved, the misjudgment risk is reduced, the endpoint equipment execution behavior, resource calling and behavior sequence are extracted, and the service performance of the terminal equipment is improved. Fine-grained security monitoring is realized, attack traceability is enhanced, a key strategy is dynamically adjusted, security adaptability is improved, strategy lag risk is reduced, multi-level data is integrated to calculate threat behavior and attack fitting degree, threat assessment fineness and response speed are enhanced, and global security situation awareness is improved.
Owner:SHENZHEN JINCHAO CLOUD CONTROL TECH CO LTD

Network security intelligent management and control system based on big data

The invention discloses a network security intelligent management and control system based on big data, and relates to the field of network security management. Comprising a data acquisition processing module, an intelligence fusion analysis module, a threat dynamic detection module, an attack deduction prediction module, a virtual mapping simulation module, an edge collaborative defense module, a defense strategy optimization module, an automatic decision execution module and a threat intelligence sharing module. According to the method, the detection capability of complex network attacks is improved, the attack path in the network environment can be visually presented, the security operation and maintenance efficiency is improved, the attack path is accurately blocked, and the attack success rate is reduced; comprehensive security event priority ranking can be realized, the scientificity of defense decision is improved, meanwhile, the system can adapt to different attack scenes, the defense efficiency is improved, it is ensured that a defense strategy always adapts to the current security situation, resource waste is avoided, and the defense cost-benefit ratio is improved.
Owner:JINAN JUBANG INFORMATION TECHNOLOGY CO LTD

Network security defense method and system based on incremental network attack analysis learning

The invention discloses a network security defense method and system based on incremental network attack analysis learning. The method comprises the following steps: collecting initial network flow data, and extracting a feature vector; and collecting real-time network flow data, performing segmentation processing based on a sliding time window, extracting time sequence association features from the segmented data, and matching the time sequence association features with the feature library to identify potential attacks or abnormal behaviors. And when the time sequence correlation feature is not matched with the feature library, marking the time sequence correlation feature as a candidate novel attack feature, calculating a mahalanobis distance between the time sequence correlation feature and a known attack feature to determine the attack variability, and dynamically adjusting the weight of the time sequence correlation feature. And inputting the adjusted feature weight and the real-time flow feature into a deep reinforcement learning detection model, and generating and updating a network security defense strategy. The scheme of the invention can effectively identify novel attack behaviors, dynamically respond and optimize defense strategies, and improve network security.
Owner:JIANGSU SIJI TECH SERVICE CO LTD

Network attack AI detection analysis method and system based on smart Internet

The invention discloses a network attack AI detection analysis method and system based on the smart Internet, and belongs to the technical field of network security protection, and the method comprises the steps: building an attack feature library through distributed edge nodes in a cooperative manner, generating feature parameters of each node based on a local attack event, and transmitting the feature parameters to a central server for dynamic fusion through encryption; constructing a multi-modal interaction graph, identifying a potential attack link based on association strength among graph nodes, and deducing an attack intention to generate a defense strategy; deploying a virtualized network environment, dynamically injecting induction characteristics, and adjusting an induction strategy in real time according to the interaction behavior of an attacker; and monitoring an abnormal mode of the user behavior sequence, triggering an AI interaction verification process and storing a defense strategy. According to the method, rapid collection and fusion of network attack features are realized, the detection delay of network attacks is reduced, the accuracy of attack prediction is improved, the flexibility and effectiveness of network attack confrontation are enhanced, and the defense intelligence and adaptive ability of the whole network are improved.
Owner:JIANGXI INST OF FASHION TECH

High-accuracy threat intelligence assisted network threat tracing method

The invention discloses a high-accuracy threat intelligence assisted network threat tracing method, which comprises the following steps: S1, collecting and preprocessing multi-source network security data, and constructing a time-marked event sequence set; s2, constructing an optimized Transform network model, and processing an attack event sequence by using position coding and time embedding; s3, a black swan optimization algorithm is initialized, and a Transform structure hyper-parameter is dynamically optimized; s4, outputting an attack event semantic vector, and constructing an attack path semantic map; s5, the intelligence information vector is embedded into a Transform hidden space; s6, calculating semantic similarity and dependency intensity, and generating an attack source candidate set and a traceability path; s7, outputting an attack traceability path, a starting point node and an information label, and generating a structured traceability report; and S8, according to the traceability result feedback, updating the black swan algorithm and the Transform model. The method is used for realizing intelligent modeling of multi-source network attack events and high-accuracy traceability analysis of attack source nodes.
Owner:GUANGXI POWER GRID CORP

Network attack detection method based on dynamic graph coding

The invention belongs to the technical field of network security, provides a network attack detection method based on dynamic graph coding, and solves the problems of poor dynamic adaptability of an attack path and missing of timing constraint in the prior art. The method comprises the following steps: constructing a dynamic threat map, extracting a triple of heterogeneous threat intelligence by using a RoBERTa model, and adding a timestamp and a confidence attribute; a dynamic graph encoder for time sequence perception is designed, semantic and evolution laws are fused through periodic time coding and a multi-head time sequence attention mechanism, and feature weights are adjusted in combination with a gating residual layer; an event-driven incremental updating strategy is adopted, and node similarity is calculated to achieve local subgraph updating; a time sequence rule base is established, three-dimensional parameter verification attack chain time sequence logic is defined, and abnormity is judged through conflict scores; and finally, integrating a graph updating module, a dynamic coding module and a constraint analysis module to realize multi-source threat feature matching and attack detection. According to the method, the adaptability of attack path evolution is improved through dynamic graph modeling and real-time increment updating.
Owner:UNIV OF ELECTRONICS SCI & TECH OF CHINA

System and Method for Improving Cybersecurity of a Network

A system and method for mitigating cyber-attacks against a target network comprising interconnected note that is implemented by Open Systems Interconnection (OSI) layers monitors the target network for detecting vulnerabilities across one or more OIS layers. a virtual network comprising a virtualized representation of the target network where the virtual network includes one or more virtual nodes that are annotated with identified vulnerabilities of one or more corresponding nods of the target network. A reference database can be configured to store records of known cyber-attacks and their corresponding mitigations where cyber-attacks on the virtual network are simulated based on records of known cyber-attacks and successful cyber-attacks. An AI engine can be configured to generate one or more mitigation actions based on simulation of the cyber-attacks before implementing the one or more mitigation actions to the target network.
Owner:THE GOVERNMENT OF THE UNITED STATES OF AMERICA AS REPRESENTED BY THE SEC OF HOMELAND SECURITY

Network attack tracing method, system and equipment based on user portrait, and medium

The invention relates to a network attack tracing method, system and device based on a user portrait, and a medium. The attack tracing method comprises the following steps: collecting interactive behavior data of a user in a Web page; performing compression and serialization processing on the interaction behavior data to generate a structured interaction log file; collecting fingerprint data of the user terminal and performing standardization processing to generate a fingerprint feature vector; based on the structured interaction log file and the fingerprint feature vector, generating a user unique identifier containing a risk level tag; performing clustering analysis on the interaction behavior data according to the unique identifier of the user, identifying an abnormal behavior mode of the abnormal user and marking an attack type; acquiring a public network IP address of an abnormal user, and positioning a geographic position in combination with an IP database; and constructing an attack traceability report based on the user unique identifier of the abnormal user, the abnormal behavior mode, the public network IP address and the geographic position. According to the invention, the user portrait can be accurately constructed, and the network attack behavior can be effectively identified and traced.
Owner:BEIJING YUAN FULCRUM INFORMATION SECURITY TECH CO LTD

Network attack tracing method and device based on threat graph, equipment and medium

The invention relates to a network attack tracing method and device based on a threat graph, equipment and a medium. The method comprises the steps of obtaining network security log data from multiple security data sources, and performing standardization processing to obtain a structured network security event data set; extracting threat entities and behavior relationships among the threat entities from the structured network security event data set to obtain an entity set and a relationship set; constructing a threat map according to the entity set and the relationship set, and performing time data slicing according to the timestamp to obtain a map snapshot and map metadata; based on a predefined attack chain template, identifying an attack chain sub-graph conforming to an attack behavior structure in the threat graph to obtain an attack chain set and a path reachability matrix; and according to the attack chain set and the path reachability matrix, attack path inversion is carried out by taking the target node as an end point, and an attack traceability path and a graph evolution process display result are obtained. By adopting the method, the network attack path can be identified and the attack source can be traced.
Owner:白宗鑫

Network attack path prediction method and system based on knowledge graph

The invention discloses a network attack path prediction method and system based on a knowledge graph, and relates to the technical field of knowledge graphs, and the method comprises the steps of multi-source heterogeneous data processing, dynamic knowledge graph construction, attack path prediction, high-confidence attack path acquisition and information feedback. According to the method, space-time reference alignment of data is guaranteed, a dynamic knowledge graph is constructed to update entity attributes in real time, a double-storage mode is adopted, the storage efficiency is improved, a graph attention mechanism and an attack path prediction model are constructed, attack paths are predicted, the attack path detection and prediction precision is improved, and the attack path detection and prediction efficiency is improved. The problem of limitation in the current network attack path prediction process is solved, the threat level of the high-confidence attack path is obtained through analysis, information feedback is carried out, updating of the dynamic graph is completed, and the accuracy, reliability and authenticity of a network attack path prediction result are guaranteed.
Owner:SICHUAN POLICE COLLEGE

Network attack detection method and system based on distributed intelligent probe

The invention provides a network attack detection method and system based on a distributed intelligent probe, and the method comprises the steps: receiving real-time flow data synchronously collected by the distributed intelligent probe at each node of a network, carrying out the inter-node interaction relation modeling processing of the real-time flow data, recognizing a flow communication mode between different network nodes, and carrying out the detection of the network attack. Generating a flow association map containing the node connection relationship and the communication frequency; carrying out abnormal communication path mining based on the flow association map, and extracting a node communication sequence with an abnormal mode by analyzing the deviation degree of a node connection relationship and the fluctuation characteristics of communication frequency; performing pattern matching processing on the node communication sequence and an attack behavior template in a preset attack feature library, calculating sequence matching similarity and generating an attack matching degree score set; and determining a network attack type and attack source node positioning information, and generating a network attack detection result. According to the invention, the practicability and effectiveness of network attack detection are improved.
Owner:SHENZHEN XIYUE ZHIHUI DATA CO LTD

Intelligent tracking and blocking method and system for network attack chain

The invention provides an intelligent tracking and blocking method and system for a network attack chain, and relates to the technical field of network security, and the method comprises the steps: collecting network flow data, building an attack chain propagation path, setting a detection breakpoint, obtaining a data sample, carrying out the causal correlation analysis, extracting a data transmission feature, and converting the data transmission feature into a behavior sequence feature; predicting an attack chain evolution path by adopting a bidirectional feature matching mechanism; a honeypot service and a flow probe are deployed to generate an attacker portrait; and formulating a defense strategy according to the attack intention to realize attack chain blocking. According to the invention, accurate identification, effective tracking and active defense of network attacks can be realized, and the network security protection capability is improved.
Owner:BEIJING YUHONG XINAN TECHNOLOGY CO LTD

Network attack active trapping method based on intelligent scheduling

The invention discloses a network attack active trapping method based on intelligent scheduling, and the method comprises the steps: constructing a dynamic honeypot environment according to a real business system mirror image, simulating the interaction logic and data characteristics of a real business system, and generating a honeypot system; analyzing a network equipment log of an access source according to the security situation awareness platform, and capturing multi-dimensional features to identify attack traffic; dynamically generating a drainage strategy according to an identification result of the security situation awareness platform, and seamlessly switching attack traffic to a honeypot system through load balancing equipment; and recording an attack behavior chain in the honeypot system, extracting an attack tool fingerprint and tracking an attacker identity. Through dynamic simulation environment construction, intelligent traffic scheduling, full-chain traceability and intelligent resource management, high-simulation trapping, accurate attack shunting, credible electronic evidence chain generation and efficient resource utilization are realized, and the active defense efficiency is remarkably improved.
Owner:BANK OF HANGZHOU CO LTD

AI agent autonomous defense system and method for network attack path prediction

The invention relates to the technical field of AI agent defense, and particularly discloses an AI agent autonomous defense system and method for network attack path prediction. An attack chain reasoning module; a risk assessment module; a path prediction module; a resource scheduling module; a defense execution module; through cooperation of a dynamic environment sensing module, an attack chain reasoning module, a risk assessment module, a path prediction module, a resource scheduling module and a defense execution module, automation and intelligentization of the whole process from environment sensing, attack analysis to defense execution are realized, manual intervention is reduced, human errors are reduced, and the defense efficiency is improved. And the attack reasoning module is used for reasoning a multi-stage attack path, so that the limitation of single-stage attack analysis is broken through, an attack logic chain of an attacker from reconnaissance and penetration to transverse movement is completely presented, the attack life cycle is comprehensively covered, and the timeliness, comprehensiveness and security of network security defense are improved.
Owner:NANJING CHOYEA INFOTECH CO LTD

Intelligent network attack surface prediction method and system based on deep learning

The invention relates to an intelligent network attack surface prediction method and system based on deep learning, and belongs to the technical field of network security and information, and the method comprises the steps: obtaining network asset information, vulnerability distribution information and external threat intelligence data in a target network environment, and carrying out the preprocessing to generate a standardized data set; inputting the standardized data set into a pre-trained deep learning model to extract a feature vector related to the network attack; reasoning and analyzing a potential attack link based on the feature vector and the knowledge graph, and combining an association relationship among a network asset node, a vulnerability node and a threat intelligence node in the knowledge graph; and finally, according to a reasoning analysis result, evaluating an intrusion path possibly utilized by an attacker, outputting an attack surface prediction result, and presenting the attack surface prediction result in the form of an attack path list. According to the scheme, a potential attack link can be subjected to deep reasoning analysis, an intrusion path possibly utilized by an attacker can be accurately predicted, and the effectiveness of network security protection is improved.
Owner:BEIJING HUAYUNAN INFORMATION TECH CO LTD

Security protection method and apparatus for customer service management system

PCT designated stageWO2025222719A1Securing communicationData setData access
The present invention relates to the technical field of network security protection. Disclosed are a security protection method and apparatus for a customer service management system. The method comprises: acquiring an employee data set, and performing permission assignment, so as to generate an employee operation permission set; performing identity verification on an access user, and determining a data management operation permission range of the access user; acquiring a sensitive data set for encryption processing, and storing same in a customer service management system; accessing data of the customer service management system, implementing an access control policy, and performing risk assessment, so as to generate a system risk level; extracting detected anomalous data, synchronizing same to a security protection network, and outputting a protection control policy; and executing the protection control policy for security assessment, regularly updating the protection control policy, and performing intelligent security protection on the customer service management system. The present invention solves the technical problem in the prior art that customer service management systems have low security protection capacity, which leads to difficulty in preventing network attacks, thus achieving the technical effect of improving the security protection capacity of customer service management systems.
Owner:SHANGHAI HANDPAL INFORMATION TECHNOLOGY SERVICE CO LTD

Security guarantee system for cross-domain communication and data sharing of network platform software

The invention relates to the technical field of computer network security, in particular to a security guarantee system for cross-domain communication and data sharing of network platform software, which comprises a data security transmission module, an identity authentication and access control module, an encryption module, a security audit and anomaly detection module and an anti-interference disaster recovery module. According to the invention, through linkage of equipment fingerprint end-to-end encryption, threat adaptive dynamic key updating and a timestamp-random number anti-replay mechanism and AI risk pre-judgment, reinforcement learning path planning, digital twinning pre-verification and fault automatic switching technologies, collaborative guarantee of key security and transmission continuity in cross-domain audio transmission is realized; encryption intensity is dynamically upgraded along with threats, a transmission path is optimized in advance, and it is ensured that the audio stream resists various network attacks and interferences in low-delay transmission.
Owner:ICLOUDSHIELD SECURITY TECHNOLOGY CO LTD

Load frequency control system attack detection method based on reinforcement learning

The invention belongs to the technical field of power system security, discloses a load frequency control system attack detection method based on reinforcement learning, and aims to improve the recognition and defense capability of a power system on complex network attacks and overcome the defects of a traditional detection method in the aspects of attack sample generation, unknown attack recognition and system adaptability. According to the method, an attack agent based on a Markov decision process is constructed, and an improved reinforcement learning algorithm is adopted to generate a high-concealment confrontation sample; designing a bimodal detection architecture fusing LSTM supervised learning and auto-encoder unsupervised learning, and introducing an adaptive weight fusion mechanism to realize attack type identification and anomaly detection; and incremental learning and a parameter dynamic adjustment mechanism are combined, so that the detection model has continuous learning and evolution capabilities. The method can be applied to a power grid dispatching center or an intelligent micro-grid, real-time monitoring and attack defense of a load frequency control system are achieved, and the operation safety and robustness of a power system are remarkably improved.
Owner:NANJING UNIV OF POSTS & TELECOMM

Network attack research and judgment method and system, program product, equipment and medium

The embodiment of the invention provides a network attack research and judgment method and system, a program product, equipment and a medium, the system deploys a plurality of agents, and the method comprises the following steps: inputting an attack sample into an attack feature extraction agent, and constructing an attack feature library based on the extracted attack features; inputting the network security log into a field extraction agent to obtain an extracted attack related field; inputting the attack feature library and the attack related fields into an attack analysis module, and obtaining attack analysis data of the attack analysis module on the attack related fields based on the attack feature library; inputting the threat intelligence data, the asset data and the attack analysis data into a comprehensive analysis report agent to obtain an analysis report including an attack result, an attack severity degree, an influence range and an attack technology; and inputting the analysis report into an attack processing module to obtain an attack processing plan. Attack research and judgment process automation is realized by utilizing the intelligent agent, the analysis, research and judgment capability on known attacks can be improved, unknown attack behaviors can be identified, and closed-loop protection measures are formed.
Owner:BEIJING TOPSEC NETWORK SECURITY TECH +2

Method and device for constructing network attack behavior chain and active defense, and computer equipment

The invention belongs to the technical field of network security, and relates to a network attack behavior chain construction and active defense method and device and computer equipment, and the method comprises the steps: collecting full-flow data and a multi-source log from a network environment, and carrying out the preprocessing of the full-flow data and the multi-source log; storing the preprocessed full-flow data and multi-source logs, and establishing an associated index; through a deep learning algorithm and an unsupervised model, abnormal traffic and attack behaviors are identified from the full-traffic data and the multi-source logs; reconstructing the fragmented attack events into a complete behavior chain through a graph neural network and a visualization mode; based on the AI model, a dynamic defense strategy is generated, and a response action is automatically executed; through time sequence prediction and a deep learning model, a future attack trend is predicted, and active defense is realized. The method improves the unknown attack detection capability, optimizes the traceability efficiency, enhances the defense initiative, guarantees the real-time performance and accuracy of network attack prediction, and has compliance adaptability.
Owner:SHENZHEN Y& D ELECTRONICS CO LTD

Information security management system based on big data

PendingCN120086768AInternal combustion piston enginesEnsemble learningProbabilistic risk assessmentAttack
The invention relates to the technical field of network information security, discloses an information security management system based on big data, and aims to solve the defects of an existing system in the aspects of data acquisition, anomaly detection, threat prediction, risk assessment and the like. The system comprises a data acquisition module for collecting various types of data in real time; the abnormal detection model is used for identifying normal and abnormal behaviors by adopting an automatic encoder AE algorithm; the threat prediction module is used for predicting a future security threat type and probability by using a recurrent neural network (RNN) algorithm; the risk assessment module comprehensively assesses the system security risk through a random forest RF algorithm; and the response decision module is used for executing corresponding safety response measures according to the evaluation result. According to the system, the big data technology is utilized, comprehensive monitoring and accurate prediction of the network security state are achieved, the efficiency and accuracy of information security management are improved, and powerful support is provided for coping with novel and complex network attacks.
Owner:广东晖曜科技有限公司

Network security event tracing method, system and device based on AI and medium

The invention discloses an AI-based network security event tracing method, system and device and a medium, and the method specifically comprises the steps: constructing a network entity association graph based on a multi-modal data set, mining the implicit association between entities through a graph convolutional network, recognizing an APT attack chain, and obtaining graph feature data; based on the multi-modal data set, an LSTM-Transform hybrid model is adopted to analyze time sequence characteristics of network traffic, slow penetration and low-frequency detection behaviors are detected, and time sequence characteristic data are obtained; based on the graph feature data and the time sequence feature data, high-value features are screened through a genetic algorithm, and cross-modal combination features are generated by using a depth auto-encoder; based on cross-modal combination features, a network environment digital twin is constructed, an attack diffusion path is simulated, and a service influence range is quantified. According to the method, accurate tracing of the network security event is realized, and the detection and tracking capabilities of complex network attacks and the intelligent level of a response strategy are comprehensively improved.
Owner:ANHUI SANQI JIYU NETWORK TECH CO LTD

Machine learning method and system based on privacy protection enhancement

The invention discloses a machine learning method and system based on privacy protection enhancement, and relates to the technical field of data processing. The method comprises the steps of monitoring real-time data streams of a plurality of data sources based on real-time input data, analyzing relationships among various data, drawing a data association network diagram, evaluating information leakage risks and privacy sensitivity of a plurality of data points by analyzing interconnection density and path distribution of nodes in the network diagram, and generating sensitivity evaluation indexes. According to the method, the security and privacy protection level in the data processing process are improved by identifying the risk points in the data in real time and specifically adjusting the noise level of the data points, and the encryption processing efficiency and security are improved by comprehensively considering the data processing efficiency, security level requirements and computing resource consumption; the stability of encrypted data is tested by simulating network attack conditions, the capability of coping with network attacks is enhanced, input data is enabled to support various data analysis tasks, and the privacy and security of the data are ensured.
Owner:JINQICHUANG (BEIJING) TECH CO LTD

Active defense system and method based on multi-protocol dynamic simulation and distributed trapping

The invention provides an active defense system and method based on multi-protocol dynamic simulation and distributed trapping. The active defense method based on multi-protocol dynamic simulation and distributed trapping comprises the following sub-steps: S1, constructing a multi-protocol dynamic simulation environment; s2, deploying distributed trapping nodes; s3, deep trapping of attack behaviors; s4, attack chain reconstruction and behavior analysis; s5, performing adaptive confusion and adversarial enhancement; s6, automatic threat intelligence production and feedback; by loading the protocol template library and initializing the state machine, the response can be dynamically generated according to the real-time session context, and dynamic simulation of various service protocols is adopted, so that the detection capability on network attacks is improved, potential threats can be captured more quickly, and the risks of missing report and false report are reduced; and through an automatic threat intelligence generation and feedback mechanism, in combination with IOC index identification, structured output and real-time response, a defense strategy can be quickly responded and adjusted.
Owner:CHINA LIFE INSURANCE CO LTD

Information physical security defense method, system and equipment based on distribution network digital twin simulation platform, and medium

The invention discloses an information physical security defense method, system and device based on a distribution network digital twin simulation platform and a medium, and belongs to the technical field of information security and control defense of the power distribution Internet of Things, and the method comprises the steps: constructing a three-dimensional channel for interaction of a physical power grid, an information model and simulation data; on the basis of a three-dimensional channel, a three-state dynamic conversion model among a steady state, a transient state and a recovery state is constructed, and multi-state automatic switching simulation is achieved through sub-region division and parallel computing; a multi-level risk modeling system oriented to various risks is constructed based on simulation results, complex attack scenes are identified, and mapping of risk types and response paths is achieved; security risk assessment and defense strategy generation verification are completed, and intelligent collaboration and continuous learning of cross-domain defense strategies are achieved through collaborative optimization. According to the method, the construction efficiency of a complex risk scene is improved, quantitative analysis of cross-domain risks such as circuit breaker mis-tripping caused by network attacks is realized, and the limitation of traditional single-domain risk analysis is broken through.
Owner:GUIZHOU POWER GRID CO LTD

Internet of Things control system and safety early warning method

The invention relates to the technical field of Internet of Things security, and discloses an Internet of Things control system and a security early warning method, and the method comprises the steps: firstly collecting equipment basis and real-time information in an Internet of Things system, then evaluating equipment risk, network security and data encryption conditions, setting an early warning threshold according to multi-aspect evaluation results and historical security data, and finally, carrying out early warning. And finally, real-time monitoring is carried out, and early warning is triggered when the risk index exceeds a threshold value. The method has obvious advantages, equipment aging and safety risks can be accurately evaluated, equipment maintenance is planned in advance, and the maintenance cost is reduced; network attacks can be effectively identified, and network security is guaranteed; the data encryption security is enhanced, and the data leakage risk is reduced; early warning is given out in time, and the system response speed is increased; and the equipment safety state can be dynamically updated, the system safety management is continuously optimized, the safety and reliability of the Internet of Things system are comprehensively improved, and the stable operation of the Internet of Things system is promoted.
Owner:SHANDONG HUAYU INFORMATION SPACE TECH CO LTD

Website AI intelligent risk assessment real-time avoiding system and avoiding method thereof

The invention discloses a website AI intelligent risk assessment real-time evasion system and an evasion method thereof. The system comprises a VPN connection module to ensure that data capture is safe and hidden; the data capturing module collects various types of information of a target website in real time; the risk feature extraction module performs multi-dimensional feature extraction; the AI risk analysis and evaluation model identifies risks from multiple aspects of images, scripts and the like and grades the risks; the risk avoiding and warning module executes a hierarchical response strategy according to a result; the feedback and model optimization module collects a feedback and sample optimization model. According to the method, website risk avoidance is realized through the steps of VPN connection, data acquisition, feature extraction, risk assessment, strategy execution, model optimization and the like. According to the method, VPN and artificial intelligence technologies are combined, website risks can be comprehensively evaluated in real time, access strategies are dynamically adjusted, complex network attacks are effectively coped, and user network access safety is guaranteed.
Owner:SHANGHAI ZUOQI NETWORK TECHNOLOGY CO LTD

Self-adaptive vulnerability protection method, device and equipment based on dynamic game

The invention discloses an adaptive vulnerability protection method, device and equipment based on a dynamic game, relates to the technical field of network security protection, and aims to solve the problem of poor protection efficiency for network attacks changing in real time. The method comprises the following steps: collecting a three-dimensional feature set of network traffic through a distributed probe cluster, wherein the three-dimensional feature set comprises a protocol stack level feature, a session time sequence feature and a protocol state machine transfer feature; inputting the three-dimensional feature set into a detection engine integrated with a generative adversarial network and a transfer learning module, and outputting a dynamically weighted target anomaly score; generating an initial protection strategy based on the game tree model and the target anomaly score, wherein the initial protection strategy comprises a dynamic firewall rule, a detection sensitivity parameter and a decoy node topology configuration; and analyzing the space-time correlation characteristics of the initial protection strategy through the space-time attention network, iteratively optimizing the parameters of the initial protection strategy in combination with an incremental learning mechanism, and generating a target protection strategy.
Owner:BEIJING HAOWANG TECH CO LTD

Power system network security threat monitoring and early warning method and device, power equipment, computer storage medium and program product

The invention relates to a power system network security threat monitoring and early warning method and device, power equipment, a computer readable storage medium and a program product, and belongs to the field of power system network security. The method comprises the following steps: acquiring historical data and real-time data; obtaining first network feature data based on historical data, performing unsupervised learning training on the initial detection model, and taking abnormal data as second network feature data; marking the second network feature data as third network feature data; marking the first network feature data to obtain fourth network feature data to perform self-supervised learning training on the model, and obtaining first network attack features to construct a network attack feature library; performing semi-supervised learning training on the model based on the first network feature data and the third network feature data to obtain a detection model, and updating a network attack feature library; and detecting real-time data based on the detection model and the network attack feature library. The method can improve the accuracy of power system network security threat monitoring and early warning.
Owner:ELECTRIC POWER RES INST CHINA SOUTHERN POWER GRID CO LTD