Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

627 results about "Network attack" patented technology

Network security situation awareness method based on artificial intelligence

The invention provides a network security situation awareness method based on artificial intelligence, and relates to the technical field of network security. Real-time monitoring and multi-source data fusion analysis are performed on a network communication behavior, a host operation state, threat alarm information and a relationship between vulnerabilities and a topological structure; constructing a threat intensity parameter, a behavior anomaly rate parameter, a vulnerability exposure degree parameter and a traffic anomaly density parameter, and calculating a risk potential energy index to realize quantitative evaluation of a network risk state; introducing an attack chain dynamic coupling index to perform dynamic analysis on a multi-stage attack evolution trend, and judging an attack chain formation risk; depicting an abnormal flow distribution concentration degree through a risk propagation convergence entropy index, and identifying concentrated penetration and critical path breakthrough risks; and defense strategies such as risk tracing, attack chain blocking and key path reinforcing are given, so that accurate recognition, trend prediction and adaptive defense of complex network attacks are realized.
Owner:CHENGDU RUIDIOU TECH CO LTD

Data transmission methods, devices, computer equipment and communication systems

This application discloses a data transmission method, apparatus, computer device, and communication system, relating to the field of communications. The method includes: generating an authentication key based on security credentials distributed by an authentication center; authenticating devices with an authentication code generated from the authentication key; and transmitting encrypted data processed by an encryption key. Thus, authentication is based on the generated authentication key, eliminating the need for devices to transmit the authentication key itself, preventing its acquisition, improving authentication key security, and reducing network attacks. The authentication center does not need to manage authentication keys and security credentials, decentralizing the authentication mechanism and reducing the complexity of key management. Furthermore, the authentication key has a small data size, meeting the storage requirements of resource-constrained IoT devices, thereby achieving secure authentication for resource-constrained IoT devices, reducing network attacks on the IoT, and improving IoT network security.
Owner:HUAWEI TECH CO LTD

Industrial internet network intrusion detection method based on pre-trained large language model

The invention provides an industrial internet network intrusion detection method based on a pre-trained large language model, and the method comprises the steps: carrying out the data preprocessing of original network flow data through protocol self-adaptive flow aggregation and session segmentation, feature screening and feature coding; constructing a stream format text data set used for training a generation model GPT-2 and a packet level classification text-label data set used for training a classification model DistilBERT; then fine tuning training is carried out on the generation model GPT-2 and the classification model DistilBERT; then calling a trained generation model GPT-2 to generate a traffic sequence, obtaining a prediction data packet, calling a trained classification model DistilBERT, performing anomaly judgment on sequence data in the prediction data packet one by one, and outputting a classification result of anomaly judgment; the active intrusion detection of first generation and then discrimination is realized. According to the method, prediction can be made before real attack traffic arrives, and network attacks are prevented.
Owner:EAST CHINA JIAOTONG UNIVERSITY

System for cyber risks evaluation

A method and system for evaluating cyber risk of an entity comprising a risk evaluation module configured to collect risk data on risks of cyber-attacks connected to SaaS, infrastructure, and legal regulations classified by geolocation, industry type, and size of the victim organization, an entity evaluation module for collecting vulnerability data on assets of the entity classified by industry type, geolocation, size and cyber threat vector vulnerabilities and a monetization engine configured to make an assessment of expected financial loss from a specified cyber-attack to an entity classified by geolocation, industry type, and size, based on the risk data.
Owner:LEVY GIL +4

Adaptive security protection method for Internet of Things terminal

The invention discloses a self-adaptive security protection method for an internet of things terminal, and the method achieves the joint perception and collaborative response of security threats of a physical side and a network side through the construction of a lightweight cross-domain feature perception and resource dynamic adaptation mechanism. According to the method, the physical service criticality and the network attack threat are quantitatively associated, and the optimal security policy is dynamically selected according to the real-time computing power state of the terminal, so that the accurate balance between the protection strength and the service continuity is realized under limited resources. By introducing a resource-aware dynamic scheduling mechanism, the Internet of Things terminal can intelligently degrade or switch a protection strategy in a high-load or high-threat scene, and service interruption caused by resource exhaustion is avoided. Finally, the identification and defense capabilities for information-physical cross-domain hidden attacks are remarkably improved, stable operation and continuous protection of the terminal under harsh resource constraints are ensured, and finally, dual guarantee of security efficiency and service reliability is realized.
Owner:STATE GRID HENAN INFORMATION & TELECOMM CO

APT network attack identification method and system

The embodiment of the invention discloses an APT (Advanced Persistent Threat) network attack identification method, which comprises the following steps: collecting multi-source data from a plurality of data sources, and filtering current attack behavior data from the multi-source data; performing multi-dimensional similarity calculation on the current attack behavior data and the APT organization intelligence in the multi-modal threat knowledge graph to obtain a comprehensive similarity, the multi-modal threat knowledge graph being obtained by modeling after the multi-dimensional attack data and the threat intelligence are fused; nodes in the multi-modal threat knowledge graph are used for representing APT organizations, TTP, used tools and attack targets, and edges connected with the nodes are used for representing relationships among entities represented by the nodes; and based on the comprehensive similarity and the multi-modal threat knowledge graph, performing attribution reasoning on the APT organization of the current attack behavior data to obtain the identity information of the attacker. According to the method, unknown threats can be identified, the identity information of an attacker can be obtained through accurate reasoning, and the utilization rate of intelligence is improved.
Owner:QI AN XIN TECHNOLOGY GROUP INC

Data annotation agent network attack identification method based on artificial intelligence

The invention discloses a data annotation agent network attack identification method based on artificial intelligence. The method comprises the following steps: collecting and preprocessing original network monitoring data; constructing a labeling task set; performing feature analysis, generating an initial category label and a corresponding confidence value, and outputting an agent labeling result; according to the confidence value of each agent, a preset weight parameter and an annotation consistency index, generating an annotation sample set; dividing the labeled sample set into a network attack identification training sample set and a network attack identification verification sample set; the improved HTAN model is trained, and a trained improved HTAN model is obtained; outputting an attack probability value and an attack category judgment result of the online detection sample; according to the method, efficient labeling, high-precision learning and real-time detection of network attack identification are realized, and the automation degree and attack identification capability of a network security protection system are improved.
Owner:SHANDONG LANGGU INFORMATION TECH CO LTD

Network attack early warning method based on abnormal behavior graph

The invention relates to the technical field of Internet of Things security, in particular to a network attack early warning method based on an abnormal behavior map. Comprising; constructing a subject-behavior-resource three-layer heterogeneous graph, establishing a low-activity baseline model based on historical data, calculating weak association strength between nodes by adopting wavelet decomposition and a signal enhancement algorithm, and identifying a latent attack chain; the attack chain features are converted into multi-dimensional vectors, and an attack collaboration time window and intensity are predicted through a vector convergence angle and a distance change rate; the vulnerability of the graph topology is quantified, the edge weight is dynamically adjusted by using a gradient descent algorithm, and high-risk nodes are isolated; the convergence parameters are fed back to the baseline model and correlation strength calculation to form closed-loop optimization; and calculating a comprehensive threat index based on three-dimensional weighting of the latent threat intensity, the convergence urgency degree and the topology anti-attack capability, and realizing layered early warning. According to the method, the APT attack detection rate is remarkably improved, and the early warning response time is shortened.
Owner:SHENZHEN YUANFEI NETWORK TECH CO LTD

Server security protection method and system based on dynamic gateway strategy

The invention relates to the technical field of computer network security, and discloses a server security protection method and system based on a dynamic gateway policy. The method aims at solving the problems that a traditional security gateway is low in protection efficiency, high in false alarm rate and difficult to cope with complex dynamic network attacks due to static rule matching, single flow analysis dimension, strategy updating lagging and poor response collaboration. The method comprises the following steps: receiving an inbound request through a security gateway agent, extracting a multi-dimensional feature, and constructing a structured traffic feature vector; and establishing a dynamic behavior baseline model based on historical normal traffic. According to the scheme, self-adaptive adjustment and minute-level response of the security policy are realized, the false alarm rate is reduced, the detection accuracy of hidden attacks is improved, the continuity of core services under high load is guaranteed, a self-evolution closed loop of'detection-response-learning 'is formed, and the intelligence and reliability of overall protection are enhanced.
Owner:SHENZHEN IBD INTELLIGENT TECH CO LTD

Reinforcement learning intrusion detection method based on space-time attention and dynamic courses

The invention discloses a reinforcement learning intrusion detection method based on space-time attention and dynamic courses, and the method comprises the steps: carrying out the dynamic weight distribution of input features in space and time dimensions through a multi-level space-time attention mechanism, and enhancing the expression capability of key features; a dynamic curriculum learning strategy is adopted to realize progressive difficulty adjustment of training samples, and the learning ability of the model is gradually improved through initial difficulty estimation, dynamic threshold adjustment and curriculum sample selection; designing a composite reward mechanism to optimize a reward signal, and combining a basic classification reward and a stability reward to promote stable convergence of the strategy; a self-evolution target network module is introduced, and dynamic update management of a target network is realized through performance monitoring, emergency update triggering and frequency self-adaption. A space-time cooperative detection closed loop is constructed, and an end-to-end intrusion detection process is realized through environment interaction, strategy optimization and online detection. The method effectively improves the accuracy and robustness of intrusion detection, and adapts to a complex network attack scene.
Owner:GUANGZHOU UNIVERSITY

Data cleaning system for terminal intelligent agent

The invention provides a data cleaning system for a terminal agent, relates to the technical field of data processing, and realizes efficient and intelligent purification of original heterogeneous data through combination of a preliminary cleaning module and a multi-model collaborative risk detection module. Four artificial intelligence models of the risk detection module, namely a security model, a sensitive privacy model, a networking large model and a poisoning detection model, work cooperatively, so that the system can accurately identify complex risks such as network attacks, personal privacy leakage, false information and data poisoning, and automatic shunting and disposal are realized based on a risk grading mechanism. And the comprehensiveness, accuracy and intelligent level of data cleaning are improved.
Owner:FIFTH ELECTRONICS RSCH INST OF MINISTRY OF IND & INFO TECH

Systems and methods for assessing criticality and risk in an operational technology network

A non-transitory computer readable medium stores instructions that cause processing circuitry to receive network data representative of devices, software, or both running on an operational technology (OT) network, calculate a criticality score the devices representing an importance of the respective device to an industrial automation process performed by an industrial automation system associated with the OT network, receive vulnerability data representing one or more known vulnerabilities that may be experienced by the OT network, calculate, based on the criticality scores and the vulnerability data, a risk score for each of the devices representative of a risk of the respective device being subject to a cyber-attack, and generate, for display via a client device, a visualization that includes at least one of the risk scores corresponding to at least one of the devices running on the OT network.
Owner:ROCKWELL AUTOMATION TECH INC

Automobile heterogeneous network intrusion detection method based on QLoRA and knowledge distillation

The invention relates to an automobile heterogeneous network intrusion detection method based on QLoRA and knowledge distillation, and belongs to the technical field of intelligent networked automobile on-board network intrusion detection safety. The technical problems that an existing method is difficult to give consideration to light weight and high precision and cannot adapt to resource constraints of a vehicle-mounted embedded environment are solved. According to the technical scheme, the method comprises the steps that self-adaptive mapping and feature extraction are conducted on original data from a CAN bus and the Ethernet, and a unified annotation data set is constructed; a knowledge distillation framework based on BERT is designed, google-bert is used as a teacher model, tiansz-bert is used as a student model, model parameters are compressed by adopting a QLoRA quantification technology, and partial layers are frozen; knowledge of the teacher model is transmitted to the student model through knowledge distillation, and training is carried out in combination with soft and hard label loss. The technical effects are that lightweight intrusion detection is realized, resource consumption is reduced, high detection precision is maintained, and various network attack threats can be identified.
Owner:CHONGQING UNIV OF POSTS & TELECOMM

Industrial network attack strategy prediction and defense decision-making system

The invention relates to the technical field of industrial control system network security, and discloses an industrial network attack strategy prediction and defense decision-making system, which comprises a semantic modeling module used for analyzing a configuration and communication file construction function and variable coupling hypergraph, and describing causal mapping from a network instruction to a physical variable; the dynamic evolution module is used for reconstructing a phase space based on the physical time sequence data, identifying an implicit coupling relationship and updating a hypergraph structure; the strategy prediction module is used for deducing a physical trajectory after instruction execution by combining the hypergraph and the phase space model, and judging a destructive attack strategy according to the maximum Lyapunov index; and the defense decision module triggers a virtual-real state bifurcation mechanism, generates an inertia compensation signal to maintain physical stability, and generates and constructs feedback data to cheat an attacker. According to the method, through cross-domain coupling modeling and dynamic deduction, physical destructiveness is accurately predicted, production maintenance and attack spoofing are considered through virtual-real bifurcation, and the reliability of defense decision making is effectively improved.
Owner:国能神福(石狮)发电有限公司

Network attack monitoring method and device based on cellular, equipment and storage medium

The invention relates to the field of attack monitoring, and discloses a cellular-based network attack monitoring method and device, equipment and a storage medium. The method comprises the following steps: acquiring to-be-monitored flow data in real time; obtaining a to-be-monitored element spore sequence based on the to-be-monitored flow data; acquiring a feature vector corresponding to the to-be-monitored element spore sequence; inputting the feature vector into a preset reconstruction model to obtain a reconstruction feature vector corresponding to the to-be-monitored element spore sequence; the reconstruction model is obtained through unsupervised training; and determining whether an attack behavior exists according to the feature vector and the reconstructed feature vector. Therefore, the method does not need to depend on the comprehensiveness of attack samples, enables the reconstruction model to find unknown threats under the condition of no labeled data, provides reliable guarantee for industrial network security, and improves the monitoring effect of attack behaviors.
Owner:STATE GRID SICHUAN ELECTRIC POWER CORP ELECTRIC POWER RES INST

Abnormal transaction identification method and device based on edge node collaboration, and electronic equipment

The invention discloses an abnormal transaction identification method and device based on edge node collaboration and electronic equipment, and relates to the technical field of distribution.The method comprises the steps that an encrypted transaction feature vector transmitted by an infrastructure end is received, a transaction request is generated based on the encrypted transaction feature vector, the transaction request is sent to a plurality of adjacent edge nodes, and the edge nodes send the transaction request to the infrastructure end; and receiving collaborative verification results of a plurality of adjacent edge nodes on the transaction request based on a preset consensus algorithm, performing abnormal transaction identification based on the collaborative verification results of all adjacent edge nodes by using a gradient boosting decision tree model, and executing the transaction request under the condition that the transaction identification result indicates that the transaction is a normal transaction. And a transaction execution result is fed back to the basic equipment end. According to the invention, the technical problem that the protection capability of a localized single-node detection system is easy to reduce for large-scale network attacks or fault conditions of individual nodes in the prior art is solved.
Owner:INDUSTRIAL AND COMMERCIAL BANK OF CHINA

Attack isolation method and system for multi-level honeynet architecture

The invention discloses an attack isolation method and system for a multi-level honeynet architecture, and relates to the technical field of attack isolation, and the method comprises the steps: carrying out the incremental processing of a first number of suspicious attack sessions if a detection statistic is greater than or equal to a preset detection threshold, and obtaining a second number of attack sessions, performing maximum likelihood estimation based on a third number of normal interaction sessions and the second number of attack sessions, determining a session category corresponding to a maximum probability result, and marking and isolating the attack sessions corresponding to the maximum probability result to obtain a fourth number of residual interaction sessions; and based on the fourth number of residual interaction sessions, dynamically adjusting virtual service configuration and interaction strategies of the multi-level honeynet nodes, updating virtual topology and bait asset distribution, and continuously guiding attack behaviors into the honeynet environment. According to the isolation method, the accuracy of attack detection is remarkably improved, so that efficient isolation and intelligence utilization of complex network attacks are realized.
Owner:POWERCHINA JIANGXI ELECTRIC POWER ENGINEERING CO LTD

Security situation awareness and self-adaptive defense system for power plant machine room

The invention discloses a power plant room-oriented security situation awareness and adaptive defense system, which adopts a layered architecture and comprises a data acquisition layer, a situation analysis layer, a decision response layer and a man-machine interaction layer. The data acquisition layer is used for acquiring multi-source heterogeneous data such as network traffic, host behaviors and physical operation parameters; the situation analysis layer performs fusion analysis on the data through a dynamic trust evaluation module, a threat evaluation module, a situation understanding module and a situation prediction module, generates a global security situation quantitative index and predicts an attack path; and the decision response layer generates a self-adaptive defense control instruction based on a predefined strategy library and a self-adaptive defense strategy engine, and drives a network security device or a process control system to execute operations such as dynamic micro-isolation and security mode switching through a response actuator. According to the method, an intelligent closed loop of perception-analysis-decision-execution is formed, and the active defense capability and the safety operation and maintenance efficiency of the power plant machine room facing complex network attacks are effectively improved.
Owner:GUODIAN ZHENENG NINGDONG POWER GENERATION CO LTD

Method and system for bidirectional authentication and session key negotiation of NFC passive lock

The invention belongs to the technical field of key agreement, and particularly relates to a bidirectional authentication and session key agreement method and system for an NFC passive lock, and the method comprises the following steps: S1, a mobile phone side generates a first temporary private key and a first random number, and carries out the first temporary private key agreement on the basis of an identity label of the NFC passive lock, the first random number, and a first base point G and a second base point P of an elliptic curve; and calculating a first temporary public key by using the first hash function, and sending the first temporary public key and the first random number to the NFC passive lock. According to the invention, on the premise that the hardware storage burden of the NFC passive lock is not increased, safe bidirectional authentication and key negotiation are realized, the capability of resisting physical attacks and network attacks is improved, and the confidentiality and integrity of communication are guaranteed.
Owner:HANGZHOU SCIENER INTELLIGENT CONTROL TECH CO LTD

Networked vehicle queue safe cruise method for coping with hybrid network attack

The invention discloses a networked vehicle queue safe cruise method for coping with hybrid network attacks, the vehicle queue comprises a head vehicle and a following vehicle, the following vehicle collects the running state data of the vehicle, obtains the running state data of other vehicles through a communication network, continuously detects the state of the communication network, and sends the detected state to the vehicle queue. Detecting whether a network attack is currently suffered or not and the type of the suffered attack, and calculating the minimum characteristic value of the topological matrix in a normal communication state, a spoofing attack state or a replay attack state according to the identified attack type; and then solving the constructed linear matrix inequality which enables the vehicle closed-loop system to be stable to obtain a feedback gain, and generating a control input signal according to the feedback gain obtained by calculation to realize accurate control of the vehicle. The feedback gain is dynamically adjusted according to the real-time state of the vehicle, so that the safety cruise control of the vehicle queue system is more effectively realized.
Owner:ZHEJIANG UNIV OF TECH

Network threat identification and defense method and system based on data enhancement and adversarial evolution

The invention provides a network threat identification and defense method and system based on data enhancement and adversarial evolution, and relates to the technical field of network security defense, and the method comprises the steps: obtaining a log stream of a network event, and carrying out the preprocessing and vectorization of the log stream; performing knowledge base RAG retrieval on the vectorized network events, and retrieving to obtain attack and defense tags of similar network events in a knowledge base; constructing cue words, inputting the cue words into the LLM reasoning model, and predicting the next network attack operation; a double-agent adversarial network mechanism is started in the LLM reasoning model, a reinforcement learning evaluation process is introduced, a multi-objective loss function is constructed, and the multi-objective loss function is used as an optimization index of an attack sample and a standard whether the multi-objective loss function is handed over to a defense agent or not; and the defense agent identifies an attack sample, and improves the discrimination capability of fuzzy attack features by optimizing cue words to obtain a discrimination prediction result. According to the invention, the modeling and prediction capability of the attack sequence is improved.
Owner:INFORMATION COMM COMPANY STATE GRID SHANDONG ELECTRIC POWER

Malicious telecontrol instruction detection method and system aiming at power system network attack

The invention discloses a malicious telecontrol instruction detection method and system aiming at power system network attacks. The malicious telecontrol instruction detection method for the power system network attack comprises the following steps: acquiring each real-time telecontrol instruction between a master station and a slave station of a power system; performing serialization based on each real-time telecontrol instruction to obtain each real-time single-row vector; inputting each real-time single-row vector into a pre-constructed malicious telecontrol instruction mixed detection model, and outputting a malicious telecontrol instruction detection result by the malicious telecontrol instruction mixed detection model; wherein the malicious telecontrol instruction mixed detection model is obtained by optimizing hyper-parameters of a Transform model on the basis of a plant rhizome growth optimization algorithm PRGO, and the malicious telecontrol instruction detection result comprises instruction types of the real-time telecontrol instructions. The malicious telecontrol instruction detection system for the power system network attack is used for realizing the malicious telecontrol instruction detection method for the power system network attack.
Owner:STATE GRID BEIJING ELECTRIC POWER CO +1

Network attack detection method and device, storage medium and electronic equipment

The invention discloses a network attack detection method and device, a storage medium and electronic equipment, and relates to the technical field of network security, and the method comprises the steps: extracting a traffic feature of network traffic, carrying out the feature compression of the traffic feature, and obtaining a low-dimensional feature, the low-dimensional feature being a feature used for reflecting the difference between attack traffic and normal traffic. And carrying out coarse-grained detection on the low-dimensional features to detect whether the network traffic is suspicious traffic, and if the network traffic is suspicious traffic, carrying out fine-grained detection on the low-dimensional features to detect whether the network traffic is attack traffic. According to the technical scheme of the invention, the real-time performance of network attack detection is improved while the efficiency and the precision are balanced through a feature compression and coarse and fine dual-granularity detection mechanism.
Owner:CHINA MOBILE GROUP DESIGN INST +1

Cyber security system utilizing interactions between detected and hypothesize cyber-incidents

An apparatus may include a set of modules and artificial intelligence models to detect a cyber incident, a simulator to simulate an actual cyber attack of the cyber incident on a network including physical devices being protected by the set of modules and artificial intelligence models; and a feedback loop between i) the set of modules and artificial intelligence models and ii) the simulator, during an ongoing detected cyber incident. An attack path modeling module is configured to feed details of the detected incident by a cyber threat module into an input module of the simulator, and to run one or more hypothetical simulations of that detected incident in order to predict and control an autonomous response to the detected incident. Any software instructions forming part of the set of modules, the artificial intelligence models, and the simulator are stored in an executable form in memories and executed by processors.
Owner:DARKTRACE HLDG LTD

Model device for data flow monitoring based on government affair system

The invention belongs to the technical field of data flow, and discloses a data flow monitoring model device based on a government affair system. By solving the problem that government affair public data generally lacks security monitoring blind spots of overall government affair public data flow monitoring, the depth and breadth of security monitoring are effectively improved, so that the problem that a traditional security protection means is difficult to deal with advanced persistent threats, large-scale sensitive data leakage and novel threats of complex network attacks is solved. Through safety supervision and safety panoramic analysis of government affair public data flow monitoring, a result after safety data analysis is analyzed according to research and judgment analysis, authorization analysis and flow supervision process analysis of flow data safety monitoring and supervision design, and cross-platform, cross-department and cross-level unified data safety situation presentation and centralized management are realized.
Owner:上海市大数据中心

Proof of work, space and time challenge for computer network attack prevention

PendingUS20260197346A1AttackNetwork attack
A method, apparatus and computer program product to protect network resources against attacks. The technique, referred to herein as a Proof of Work, Space and Time (POWST), prevents large scale attacks by making them computationally and resource-intensive, thus increasing the cost of launching such attacks so as to make them cost-prohibitive. More specifically, the approach herein leverages a Euler function to implement a challenge that involves both proof of work and time, as well as proof of space. This challenge is configured to not only consume CPU cycles, but also does so for a required duration (a “challenge duration”) while simultaneously consuming memory (RAM) space (a “challenge space”) on the attacking machine.
Owner:AKAMAI TECHNOLOGIES INC

Intelligent micro-grid network attack detection method and system based on block chain, wavelet transform and support vector machine, medium and processor

PendingCN121441527ACircuit arrangementsKernel methodsSmart microgridAttack
The invention discloses an intelligent micro-grid network attack detection method and system based on a block chain, wavelet transform and a support vector machine, a medium and a processor, and relates to the field of power grid network attack detection. The method aims at solving the problems that normal and attack exception are difficult to distinguish, the missing and false detection rate is high, and data are tampered easily in a traditional method. The method comprises the following steps: collecting and preprocessing DC micro-grid data; decomposing into high and low frequency components through wavelet transform, and extracting amplitude, frequency and energy related characteristic parameters; constructing and training a support vector machine model for real-time attack detection; and after detecting full-process data hash processing, uploading the data to the block chain, and storing evidence based on a PoA consensus mechanism. According to the method, attack features are accurately captured through wavelet transformation, high-accuracy classification is realized in combination with the SVM, the block chain guarantees data credibility, a micro-grid dynamic scene can be quickly responded, and the network security protection capability is improved.
Owner:ELECTRIC POWER RES INST OF GUANGXI POWER GRID CO LTD

Object detection method and data storage unit detection method

This specification provides an object detection method and a data storage unit detection method. The object detection method includes: performing anomaly detection on multiple network addresses to determine abnormal network addresses, wherein any one of the multiple network addresses exists in at least two network address sets corresponding to target objects, and each target object corresponds to a network address set; determining an abnormal network address set based on the abnormal network addresses and the association between the multiple network addresses and the network address sets, and identifying the target objects corresponding to the abnormal network address sets as abnormal objects; thereby accurately and quickly locating abnormal objects that have suffered network attacks, avoiding the problem of not being able to accurately identify abnormal objects that have suffered network attacks.
Owner:ALIBABA CLOUD COMPUTING CO LTD

Adaptive intrusion detection method based on CDIVAE and bidirectional time series model

This invention discloses an adaptive intrusion detection method based on CDIVAE and a bidirectional temporal model, belonging to the field of network attack detection technology. It uses the GWR algorithm to filter and cluster source domain data, removing a large amount of duplicate data and extracting a clearly distributed and relatively small subset of source domain data. A Gaussian mixture conditional domain-invariant variational autoencoder (GMI) is used to reduce the difference in posterior distribution between the source and target domains. Finally, an intrusion detection is performed using a fusion neural network BRN-BiLSTM, which combines a bidirectional preservative network encoder and a bidirectional long short-term memory network. The BRN first applies bidirectional temporal weighting to the data, and then the BiLSTM identifies and classifies the time-weighted data. The memory unit and gating unit effectively capture data dependencies. This invention achieves better domain-invariant feature extraction and data distribution alignment, and also exhibits better cross-domain intrusion detection performance.
Owner:YANSHAN UNIV