Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

471 results about "Network behavior" patented technology

Network behavior analysis (NBA) is a way to enhance the security of a proprietary network by monitoring traffic and noting unusual actions or departures from normal operation.

Information security management method based on data processing

The invention discloses an information security management method based on data processing, and particularly relates to the field of information security management, comprising multi-source heterogeneous data acquisition, multi-dimensional feature index calculation, comprehensive threat detection calculation and adaptive threat decision. According to the method, the covert communication channel is accurately identified by constructing the encrypted traffic multi-mode detection model and combining protocol fingerprint entropy and traffic self-similarity analysis; an improved entropy weight fusion algorithm is adopted, collaborative analysis of system process abnormity, network behavior offset and hardware degradation is achieved, and a cross-dimension attack chain is reconstructed; a storage medium physical feature-cryptographic module runtime joint monitoring mechanism is created for the first time, hardware layer physical attacks and cryptographic side channel vulnerabilities are synchronously defended through temperature-delay correlation evaluation and key derivation density analysis, a complete attack surface from a physical layer to an application layer is covered, and the security is improved. And the detection precision and the response real-time performance of the complex threats are obviously improved.
Owner:ANHUI WEIZHI INTERNET OF THINGS TECHNOLOGY CO LTD

Network attack dynamic detection and security protection method and system based on artificial intelligence

The invention relates to the technical field of network attacks, in particular to a network attack dynamic detection and security protection method and system based on artificial intelligence, and the method comprises the following steps: S1, data collection: collecting a multi-protocol communication data flow of network equipment, and generating a multi-dimensional feature vector; s2, constructing a cross-protocol behavior graph: generating a dynamically updated network behavior graph; s3, anomaly detection: identifying an abnormal behavior mode through the deep residual sequential network, and outputting threat evaluation parameters; s4, protection strategy generation: generating a dynamic protection instruction set through a reinforcement learning decision algorithm; and S5, protection execution: executing the dynamic protection instruction set to complete safety protection operation. According to the method, the multi-protocol fusion behavior graph is constructed, and an abnormal detection mechanism of graph nerve and differential modeling and a dynamic response strategy driven by reinforcement learning are introduced, so that high-precision identification and efficient protection of network attacks are realized.
Owner:TIBET LANGJIE INFORMATION TECH CO LTD

Network security situation awareness method and system

The invention relates to the technical field of network security, in particular to a network security situation awareness method and system, and the method comprises the following steps: extracting a source IP address and a target IP address based on a network behavior record, carrying out the statistics of the number of used ports, the transmission direction and the time interval value, analyzing the direction change times and the time interval difference, and screening abnormal communication pairs. And generating an abnormal communication pair set. According to the invention, through analyzing port usage, transmission direction and time interval value, deeply mining communication features, screening abnormal communication pairs and improving identification accuracy, dividing a time sequence window, analyzing rate fluctuation and frequency distribution, locking an unstable time window, combining with a multi-dimensional data classification behavior mode, and extracting a switching path and priority, a multi-dimensional data classification behavior mode is combined. Potential threat paths are identified independently, global threat situations are identified through node interaction relation statistics and correlation analysis and an expansion range, threat assessment precision and efficiency are enhanced, and comprehensive and reliable risk protection capability is provided for network managers.
Owner:JIANGSU ZHOUQI DIGITAL TECH CO LTD

Network traceability data processing method, system, equipment and medium

The invention discloses a network traceability data processing method, system and device and a medium, and the method comprises the steps: collecting network data, carrying out the preprocessing of the network data, and generating the preprocessed network data; extracting behavior characteristics from the preprocessed network data to obtain network behavior characteristics; constructing an attack graph according to the obtained network behavior characteristics, and forming a dynamic graph representing an attack path; and carrying out traceability decision on the dynamic atlas, and positioning an attack source and an attack path through the traceability decision. Through the technical means of six-dimensional feature vector construction, quantum derivation genetic algorithm optimization detection and attack atlas construction through the tense graph convolutional network, the problems of data dimension missing, correlation analysis lagging and insufficient traceability precision are effectively solved.
Owner:GUANGXI POWER GRID CORP

Backtracking analysis model construction method based on attack chain

The invention relates to the technical field of data processing, in particular to a backtracking analysis model construction method based on an attack chain, which comprises the following steps that: a kernel layer security agent acquires process, file and network behavior characteristics in a hardware isolation environment, and generates an event tuple; the tensor network pipeline performs three-dimensional decoupling mapping on the tuple into a behavior fingerprint vector, an orthogonalization noise feature and an asymmetric adjacent tensor, and compresses the behavior fingerprint vector, the orthogonalization noise feature and the asymmetric adjacent tensor into a space-time topology tensor block; the reinforcement learning controller constructs a directed acyclic graph based on the tensor blocks, calculates connectivity loss and outputs an event risk score; the dynamic routing engine constructs a decision tree model according to the risk mark, the burst frequency and the correlation entropy, and implements three-level shunting and a multiple simulation system to generate an anti-interference index; and when the deviation between the physical trajectory and the digital model exceeds the tolerance, the closed-loop feedback weight coefficient updates the loss function parameter and adjusts the channel resource weight. And the problem of threat discovery delay caused by attack chain breakage under massive events is solved.
Owner:HUANENG INFORMATION TECH CO LTD

CVOCA feature extraction method and system based on multi-modal large model

The invention discloses a CVOCA feature extraction method and system based on a multi-modal large model, and belongs to the technical field of multi-modal feature extraction. Data preprocessing: processing the input data to generate standardized input; feature unified representation: utilizing a cross-modal unified encoder to map visual, text and time series data to a unified feature space; feature optimization: dynamically adjusting modal weight based on a dynamic feature optimizer to realize efficient feature fusion; carrying out context sensing modeling, and capturing long-range time sequence dependence; carrying out adversarial optimization, and improving the robustness of the model through adversarial training; the feature storage and updating system adopts an expert network and a gating mechanism to realize dynamic updating of a feature library; according to the method, the defects of an existing network behavior analysis technology in the aspects of multi-modal data fusion, calculation efficiency, anti-robustness and dynamic adaptability are overcome, and the technical performance and the application value are improved.
Owner:EVERSEC BEIJING TECH +1

Active Deep Learning Core with Locally Supervised Dynamic Pruning and Greedy Neurons

A computer system for adaptive operation of deep learning networks through hierarchical supervision, meta-level pattern tracking, cross-network signal coordination, and selective activation prioritization. The system operates a layered neural network monitored by a hierarchical supervisory system that collects activation data, identifies operational patterns, implements architectural modifications, detects network sparsity, coordinates pruning decisions, and manages resource redistribution. A meta-supervisory system tracks supervisory behavior, stores successful pruning and modification patterns, and extracts generalizable optimization principles. The system manages signal transmission pathways that enable direct communication between non-adjacent network regions, with signal modification and temporal coordination. A greedy neural system selectively processes activation patterns based on utility metrics and includes a competitive bidding manager to allocate limited computational resources to high-value signals. This architecture enables real-time optimization of network behavior and resource usage while maintaining operational stability and responsiveness across diverse applications.
Owner:ATOMBEAM TECH INC

Multi-factor dynamic authentication internet of things network security access platform

The invention relates to the technical field of Internet of Things, and discloses a multi-factor dynamic authentication Internet of Things network security access platform, which adopts a multi-factor authentication mechanism, combines biological characteristics, behavior characteristics and environment characteristics of equipment, performs identity verification through biological recognition, equipment fingerprints and behavior analysis, and utilizes a dynamic authentication strategy. Detecting an abnormal IP behavior and triggering a security policy by adopting a dynamic IP binding technology, combining with equipment fingerprint identification and learning and analyzing an equipment network behavior mode; a dynamic key management mechanism is adopted, and keys are automatically generated, distributed and updated according to different devices, application scenes and communication requirements; machine learning and artificial intelligence technologies are utilized to comprehensively analyze historical access data, abnormal behavior modes, environment security states and the like of equipment, and the security risk of equipment access is automatically evaluated if suspicious equipment is detected. The method has the advantage of improving the security of the Internet of Things.
Owner:卞玉捷

Network space security risk intelligent identification method and system

The invention discloses a network space security risk intelligent identification method and system. The method comprises the following steps: deploying traffic collection equipment at key network nodes and boundary equipment, and collecting network traffic data and log data; extracting network behavior features and log key fields, and constructing a data feature model; performing vectorization processing based on the data feature model, performing traffic classification by using a deep neural network, and identifying a device type and a device identifier; carrying out noise reduction, redundant information removal and standardization processing on flow data in the data feature model to generate standardized data and storing the standardized data in a vector database; entity extraction is carried out on the standardized data, a knowledge graph is constructed, data distribution is analyzed through a Gaussian mixture model, the probability of abnormal behaviors is calculated in combination with historical data, and attack risks are calculated based on Bayesian decision; and generating an alarm according to the calculated attack risk, tracing the historical record of the attack risk in the knowledge graph, sending a blocking instruction, and identifying the security risk of the cyberspace.
Owner:STATE GRID HEBEI ELECTRIC POWER CO LTD +3

Network security threat intelligent detection method based on big data analysis

The invention relates to the technical field of network security, and discloses a network security threat intelligent detection method based on big data analysis, and the method comprises the steps: collecting network equipment flow log data, constructing a network behavior space-time fusion matrix, calling an optimal threat detection algorithm, and carrying out the dynamic feature dimension alignment through an innovatively designed dynamic feature dimension alignment mechanism. The problem of tensor structure mismatching caused by sampling frequency difference of asset static data and network flow data in a traditional scheme is solved, a self-adaptive tensor interpolation technology is adopted, mapping of dynamic and static logs in the space-time dimension is achieved, systematic deviation during feature fusion is reduced, the accuracy of subsequent threat analysis is improved, and the risk of threat analysis is reduced. Through the established network behavior time-space fusion matrix, the asset service topology, the vulnerability fingerprint and the real-time traffic behavior are subjected to three-dimensional association modeling for the first time, the behavior chain characteristics of an attacker in the transverse movement and permission improvement process are described, and the attack path reduction capability of advanced sustainable threats is improved.
Owner:余伟

Network traffic data security assessment method and system based on deep learning

InactiveCN120455172ASecuring communicationNeural learning methodsProbabilistic risk assessmentData set
The invention provides a network traffic data security assessment method and system based on deep learning. The method comprises the following steps: converting original network traffic data into a graph structure data set comprising a topological structure, node attributes and time sequence behaviors; in the process, the time-space fusion input tensor is formed through the association strength between adjacent matrix and Laplacian matrix coding network entities and the fusion of time sequence characteristics extracted by time window slices. Compared with traditional flow analysis which only pays attention to a single protocol or a rate threshold value, the method achieves global relevance expression of network behaviors through graph structure modeling. Through graph structure modeling, multi-dimensional feature fusion and probabilistic risk assessment, the method can adapt to dynamic change of network topology and continuous evolution of an attack mode, so that a final assessment result is more accurate.
Owner:URUMQI VOCATIONAL UNIV

Intelligent detection method for network security vulnerabilities based on artificial intelligence and big data

The invention relates to a network security vulnerability intelligent detection method based on artificial intelligence and big data, and the method comprises the steps: carrying out the dynamic time synchronization processing of multi-modal network security data, and generating a multi-source data flow with aligned time sequences through cross-modal correlation analysis; extracting cross-modal features from the data stream, and performing semantic fusion on the cross-modal features in combination with a vulnerability knowledge graph to generate a multi-dimensional feature vector; training the multi-dimensional feature vector through a hybrid model to obtain a vulnerability detection model, detecting real-time network behavior data by using the model, and outputting a vulnerability probability and an abnormal risk score; and performing automatic vulnerability verification according to the vulnerability probability and the abnormal risk score to obtain a verification result, and updating the vulnerability detection model according to the result. The system can effectively improve the accuracy, timeliness and stability of network security vulnerability detection and reduce the false report and missing report rate through multi-modal data collaboration, hybrid model dual detection and closed-loop optimization mechanisms.
Owner:YANTAI VOCATIONAL COLLEGE +1

Thermal heat supply system defense collaborative protection method and system based on digital twinning

The invention discloses a digital twinning-based thermal heat supply system defense cooperative protection method and system, particularly relates to the technical field of industrial control system safety, and is used for solving the problems of hidden attack missing detection and response delay caused by splitting of energy flow and data flow in an existing protection mechanism. Physical-network behavior collaborative verification is realized by constructing a digital twinborn model, and precise protection is realized by quantifying coupling failure characteristics of energy flow and instruction flow. The method specifically comprises the following steps: collecting production data, industrial control logs and network traffic; constructing a digital twin model to simulate expected behaviors of equipment, communication and physical states; comparing and detecting abnormal data in real time; extracting a thermodynamic potential gradient characteristic quantity and a path integral characteristic quantity from the abnormal data; calculating a covariant difference value of the two characteristic quantities, and judging an external attack when the covariant difference value exceeds a threshold value; when an attack is triggered, a micro-isolation gateway is deployed, dynamic access control is implemented based on an equipment fingerprint, a user behavior sequence and an environment fingerprint, and an attack chain is blocked.
Owner:JINAN THERMAL CO LTD

Social network privacy data protection method and system

The invention relates to the technical field of data processing, and provides a social network privacy data protection method and system, and the method comprises the steps: obtaining to-be-encrypted privacy data, and obtaining a keyword popularity coefficient and a sensitivity weight coefficient according to the privacy data; acquiring behavior characteristics and basic information of a user group, and acquiring a group portrait index according to the behavior characteristics and the basic information; acquiring network behavior activeness, equipment characteristics and historical behavior information of the target user, and acquiring personal characteristics of the target user according to the network behavior activeness, the equipment characteristics and the historical behavior information; according to the keyword popularity coefficient, the sensitivity weight coefficient, the group portrait index and the personal characteristics of the target user, obtaining the encryption level of the privacy data; and calling different encryption algorithms to encrypt the privacy data according to the encryption level. According to the method, different encryption algorithms are called for encryption for the privacy data of different encryption levels, and the dynamic adaptability of encryption protection of the privacy data of the social network is improved.
Owner:HUNAN VOCATIONAL COLLEGE OF SCI & TECH

Industrial control and infrastructure defense cooperation method and system based on digital twinning

The invention provides an industrial control and infrastructure defense cooperation method and system based on digital twinning, and relates to the technical field of defense cooperation. The method comprises the following steps: based on a digital twinning technology, collecting sensor data in an industrial control system, and identifying abnormal fluctuation of equipment operation to obtain abnormal activity information; the occurrence frequency and intensity of the deviation data are analyzed, and the network data transmission security of the industrial entity is optimized to obtain security protocol optimization configuration; reconfiguring the network access authority, and monitoring the new access mode and the data flow in real time to obtain an access control optimization state; monitoring network behaviors by using an isolated forest algorithm, and quantitatively evaluating potential internal and external threats to obtain a threat evaluation update log; and adjusting the data acquisition frequency and the processing process based on the update log, and obtaining a dynamic cooperative defense mechanism by updating network defense and response rules. According to the invention, the early warning and response capability of the industrial control system can be optimized.
Owner:JINQICHUANG (BEIJING) TECH CO LTD

Automatic sensing model method and system for illegal access in network security isolation area

The invention provides an automatic perception model method and system for illegal access in a network security isolation area, and belongs to the technical field of computer systems based on specific calculation models.The method comprises the steps that firstly, a network topological graph matrix of the security isolation area is constructed, an equipment asset list is established, and then distributed flow collection nodes are deployed to obtain real-time network data; a deep packet detection technology is used for extracting features to establish an equipment behavior baseline library, a multi-target risk assessment function is used for carrying out risk grade division on equipment, a multi-layer perceptron and a time sequence anomaly detection algorithm are used for identifying abnormal communication, and an equipment fingerprint identification mechanism based on physical layer characteristics is established to verify the legality of the identity of the equipment. A security isolation intelligent sensing network model is utilized to analyze network behaviors, a multi-dimensional abnormal scoring system is constructed to calculate risk scores, a response mechanism based on a rule engine is realized, a federal learning technology can be selectively adopted to optimize the model, and an all-dimensional and multi-level illegal access automatic sensing protection system is formed.
Owner:BEIHAI FORECASTING CENT OF STATE OCEANIC ADMINISTRATION ((QINGDAO MARINE FORECASTING STATION OF STATE OCEANIC ADMINISTRATION) (QINGDAO MARINE ENVIRONMENT MONITORING CENT OF STATE OCEANIC ADMINISTRATION))

Private network dynamic access control method and system

The invention discloses a private network dynamic access control method and system, and relates to the technical field of network security and access control. The method comprises the following steps: acquiring equipment behavior data and network flow data in a private network, performing feature construction, and generating equipment trust features and network behavior features; and carrying out multi-dimensional risk assessment model training based on the equipment trust features and the network behavior features, carrying out real-time risk assessment on access requests or entities in the private network through the trained multi-dimensional risk assessment model, and generating a real-time risk score through a weighted aggregation function. According to the invention, through the multi-modal feature fusion model based on an attention mechanism, deep association of static attributes and dynamic behavior features of equipment is realized, and a real-time risk score is generated in combination with a multi-dimensional risk assessment model and a weighted aggregation algorithm. The limitation that in traditional access control, the evaluation dimension is single, the static strategy lags behind, and dynamic threats cannot be reflected is effectively overcome, and the accuracy and interpretability of private network access risk perception are remarkably improved.
Owner:GUANGZHOU TRUSTMO INFORMATION SYST CO LTD

X86 industrial control mainboard identity authentication system based on multi-mode fusion

The invention discloses an X86 industrial control mainboard identity authentication system based on multi-mode fusion, which relates to the technical field of mainboard identity authentication, and comprises the following steps: acquiring a secret key, generating a dynamic hardware fingerprint by combining cache topology and instruction delay, collecting physical unclonable function characteristics of power supply noise and clock jitter, and generating a circuit fingerprint; generating a firmware execution track, recording dynamic behaviors of a call chain and interrupt processing delay, and constructing a firmware runtime feature library; collecting spatio-temporal characteristics, generating environment fingerprints in combination with a geo-fencing technology, capturing time sequence characteristics, and generating a network behavior portrait in combination with a device topological relation; timestamp synchronization is carried out; simulating a fingerprint data tampering attack; and carrying out weighted fusion on the static features and the dynamic features. The hardware feature acquisition module, the firmware behavior acquisition module and the environment feature acquisition module are arranged, and physical unclonability of circuit fingerprints and time sequence features of firmware behaviors are combined, so that attacks are effectively resisted.
Owner:深圳市凌壹科技有限公司

Information comprehensive security protection method, system and equipment for data security

The invention discloses an information comprehensive security protection method, system and device for data security, and relates to the technical field related to data security protection.The method comprises the steps that multi-source assets are comprehensively detected, and a dynamic asset ledger is established; traversal is carried out by using the industry security baseline, asset network vulnerabilities are identified, and a difference vulnerability data list is established; constructing a double-risk matrix including compliance weight, attack and defense weight and comprehensive risk value; and analyzing a network behavior map through a situation awareness engine, identifying an abnormal behavior and an attack path, determining a risk event type and an event level, matching a collaborative response path, and sending collaborative response information according to the collaborative response path for connecting a multi-role collaborative department to perform security collaborative isolation processing. The technical problems of insufficient asset visibility, compliance and attack and defense separation and low response efficiency in the prior art are solved, and the technical effects of comprehensive dynamic asset management and control, accurate quantification of security risks and intelligent collaborative quick response are achieved.
Owner:ZHEJIANG CHUANGZHI TECH CO LTD

Photovoltaic inverter system parameter identification method based on ARMAX model and least square method

The invention belongs to the technical field of new energy power system modeling and control, and discloses a photovoltaic inverter system parameter identification method based on an ARMAX model and a least square method, and the method comprises the steps: collecting the lag time sequence data of the control input and output current of a photovoltaic inverter, constructing an ARMAX model of a multi-lag structure, and carrying out the recognition of the parameters of the photovoltaic inverter system. Estimating model parameters by adopting a least square method; constructing an adversarial data set by injecting watermark disturbance signals with statistical characteristics, and realizing fine modeling and difference prediction of system output behaviors; a double-layer variance detection mechanism is constructed based on a watermark model, and effective recognition of network behaviors such as replay attacks and harmonic forgery is achieved. The method aims at achieving high-precision modeling of dynamic response characteristics of the photovoltaic inverter and real-time detection of network attacks, can be deployed on a new energy edge control node, achieves cooperative operation of model identification, system prediction and attack detection, and has good real-time performance, robustness and engineering application value.
Owner:NANJING UNIV OF POSTS & TELECOMM

Dynamic honey spot evolution method and system based on behavior fingerprint fusion

The invention relates to the technical field of dynamic honey point evolution, in particular to a dynamic honey point evolution method and system based on behavior fingerprint fusion, and the method comprises the following steps: S1, deploying a plurality of honey point nodes and monitoring probes for collecting behavior information in a plurality of data sources, such as network traffic, host logs and user sessions, the behavior fingerprint acquisition module performs preprocessing and feature extraction on the data, and constructs a graph structure representing network entity and activity association; s2, then, a GNN fusion engine module carries out training and reasoning on the association graph based on a graph neural network, and potential threat feature values of network nodes or user behaviors are extracted; and the finally output fusion result can reflect an attack link and an attacker behavior mode which possibly exist in the current network environment. According to the method, network behavior fingerprints are extracted from multi-source data, association fusion analysis is performed by using a graph neural network, and honey spot deployment and dynamic function evolution are realized.
Owner:积至(海南)信息技术有限公司

Network security protection management system and method based on big data

The invention discloses a network security protection management system and method based on big data, and relates to the technical field of network security management, and the method comprises the steps: collecting industrial protocol layer data, physical sensor data and process parameters, extracting network behavior features, physical features and process correlation features, and constructing an industrial security feature vector; according to the security weight coefficient and the industrial security feature vector of the current process stage, calculating a threat score of the equipment, and dynamically adjusting a threat level through a three-level verification mechanism; constructing an equipment dependency graph, performing risk diffusion calculation based on the adjacent matrix and the attenuation coefficient, and generating a risk diffusion priority list to adjust an isolation strategy; an improved multi-target genetic algorithm is adopted to solve a Pareto optimal solution set, an equipment recovery sequence and a process parameter adjustment scheme are determined, and a recovery instruction is issued to realize safe recovery, so that the dynamic perception and accurate defense capability for industrial network threats is improved, and the safety and stability of industrial production are guaranteed.
Owner:JIANGXI YUSHAN EVERGREEN CEMENT CO LTD

Heterogeneous event association representation model construction method, system and equipment based on attack stage semantic alignment

The invention provides a heterogeneous event association representation model construction method, system and device based on attack stage semantic alignment, and the method comprises the following steps: extracting six-tuple features from an obtained inter-host connection log, and obtaining inter-host alarm log data with unified representation; constructing an abnormal log fragment sequence between the hosts based on the alarm log data between the hosts; mapping the inter-host abnormal log fragment sequence to obtain an inter-host attack stage; eight-tuple features are extracted from the obtained operation logs in the hosts, and operation log data, represented in a unified mode, in the hosts are obtained; constructing a sensitive behavior log fragment sequence in the host based on the operation log data in the host; mapping the sensitive behavior log fragment mapping in the host to obtain an attack stage in the host; on the basis of semantic alignment of heterogeneous security events, associating an inter-host attack stage with an in-host attack stage according to topological features, and constructing a heterogeneous event association representation model; according to the method, an observation blind area existing in a single log source can be effectively overcome, network behaviors such as network scanning and vulnerability utilization and activities in a host such as script execution and permission promotion can be captured at the same time, and therefore more comprehensive and more complete restoration of the multi-step attack process is achieved.
Owner:XI AN JIAOTONG UNIV

Network adaptive video conference transmission optimization method and system

The invention relates to the field of network communication, and particularly discloses a network self-adaptive video conference transmission optimization method and system, and the method comprises the steps: systematically analyzing a historical data sequence of a network state, and extracting a deep trend and mode of a network behavior from the historical data sequence; meanwhile, different requirements of the type of the current conference video frame on transmission parameters (especially code rates) are fully considered, and the key information is fused into a decision-making process. Through a specially designed fusion model, the historical evolution trend of the network state and the specific requirement of the current video content can be intelligently subjected to interactive perception and cooperative processing, so that a video target code rate which can adapt to future network fluctuation and can meet the current picture quality requirement is generated. Based on the dynamically optimized target code rate, the system further determines an appropriate target resolution and an appropriate target frame rate, and the video is coded and transmitted.
Owner:SHENZHEN MINRRAY IND CORP LTD

Network management method and system for Openharmony equipment

The embodiment of the invention discloses a network management method and system of Openharmony equipment, the method is applied to the network management system, the system comprises embedded equipment, a gateway, a credible verification platform and a terminal management platform, the embedded equipment forms a local area network through a distributed soft bus, the embedded equipment comprises a security chip, and the security chip is connected with the gateway through a network interface. The security chip generates a trusted measurement message according to the behavior information of the network behavior, the hardware measurement information and the trusted measurement result; the credibility verification platform judges whether the embedded equipment is credible or not according to the credibility measurement message forwarded by the gateway, determines a credibility judgment result and sends the credibility judgment result to the terminal management platform; the terminal management platform determines a management strategy according to the credible judgment result; and the gateway is used for managing and controlling the network behavior of the embedded equipment in the local area network according to the management strategy. According to the technical scheme provided by the invention, the security and reliability of the local area network can be ensured, and meanwhile, the credible security of the network behaviors of the network equipment of the local area network can be ensured.
Owner:HONGHU WANLIAN (JIANGSU) TECH DEV CO LTD +1

Data filtering method and system for digital twin industrial control safety target range

The invention discloses a data filtering method and system for a digital twin industrial control safety target range. The method comprises the following steps: firstly, marking an IP address of an industrial control system network in a segmented manner; feature extraction is carried out on the network behavior data of each IP segment, and splicing is carried out on the IP segment label to serve as a feature sample for constructing an industrial control network security identification model; a plurality of inverted residual modules with the same structure are adopted as core construction units, network behavior features in the feature samples are extracted and learned, and classification training is carried out; deploying the trained industrial control network security identification model to a pre-filtering module of a digital twin industrial control security target range, and carrying out classification, identification and filtering on network behavior data flowing in each IP segment in real time; and the misjudged sample is subjected to backtracking analysis, and the IP marking rule is updated. According to the technical scheme, the accuracy of network behavior data identification can be improved, so that the effectiveness of industrial control system simulation is improved.
Owner:STATE GRID HENAN ELECTRIC POWER ELECTRIC POWER SCI RES INST +2

Cross-platform user behavior analysis method and system based on transfer learning

The invention provides a cross-platform user behavior analysis method and system based on transfer learning, and relates to the technical field of network security, first, historical network behavior record data of a source domain security platform and real-time network behavior flow data of a target domain security platform are obtained, the historical network behavior record data comprise security behavior sequences of source domain users in different access scenes, and the real-time network behavior flow data are stored in the target domain security platform; the method comprises the following steps of: performing cross-domain security feature extraction on two types of data, constructing a cross-domain security behavior association graph, migrating source domain historical malicious behavior mode knowledge to a target domain through a migration learning model based on the graph, generating cross-platform migration security features, and performing cross-domain security feature extraction on the target domain historical malicious behavior mode knowledge. And calling a security behavior analysis model to carry out joint modeling and time sequence security association analysis, identifying an abnormal security behavior mode of a target domain user, and finally matching a network security disposal rule base according to the abnormal mode, generating and issuing a protection strategy, and realizing real-time risk interception.
Owner:LESHAN NORMAL UNIV

Supplier behavior real-time sensing and monitoring method and device and electronic equipment

The invention relates to a supplier behavior real-time sensing and monitoring method and device and electronic equipment. The method comprises the steps of collecting and preprocessing supplier multi-source heterogeneous data in real time, dynamically capturing a Binlog of a MySQL database through a Flink CDC framework, obtaining service behavior data in real time, collecting text log data through a Flume framework, and transmitting network behavior data in real time. Integrating the structured data, the unstructured data and the semi-structured data, and constructing a unified data transmission channel; constructing a multi-dimensional user portrait; comparing the semantic similarity between the bidding file and the bidding requirement, and triggering compliance early warning when the matching degree is lower than a threshold value; analyzing a supplier cooperation network, and marking a cluster group with abnormal transaction frequency and irrelevant business fields as a cross-bidding risk; and analyzing the access behavior sequence, and detecting a malicious access pattern to generate a malicious access alarm. According to the supplier behavior monitoring system and method, real-time performance, accuracy and multidimensional performance of supplier behavior monitoring are achieved through the architecture of multi-source heterogeneous data real-time integration, multi-dimensional portrait construction and intelligent risk identification.
Owner:CHINA ACADEMY OF RAILWAY SCI CORP LTD +1

Intelligent influenza early warning system based on community multi-modal data fusion

The invention relates to the technical field of infectious disease monitoring and early warning, and discloses an intelligent influenza early warning system based on community multi-modal data fusion. The community-level multi-modal data fusion architecture is constructed, medical health data, environmental data, crowd activity data and network behavior data are integrated, spatial-temporal features are dynamically extracted and fused in combination with a deep learning model, and the problem of community monitoring blind areas caused by a single data source of an existing early warning system is solved; a long short-term memory network and convolutional neural network cascade architecture is utilized to capture a localized propagation rule, and the defect that a region-level prediction model cannot adapt to community heterogeneity is overcome; the risk score is generated in real time, the grading response instruction is triggered, a'monitoring-early warning-intervention 'closed loop is established, the early warning timeliness is remarkably improved, a basic-level response chain scission gap is filled, early prevention and control of flu outbreak are finally achieved, and public health resource consumption is reduced.
Owner:武之琳

Safety operation full-process automatic closed-loop method and system driven by safety agent

The invention relates to the technical field of network security, in particular to a security operation full-process automatic closed-loop method and system driven by a security agent, and the method comprises the following steps: collecting network behavior data, including network traffic, system logs and user behavior data, from various network devices, security devices and log systems in real time; performing cleaning, denoising and standardization processing on the original data by using a natural language processing technology; the method has the beneficial effects that the full-process automatic closed-loop management from threat detection, analysis, response to feedback is realized by constructing the security agent and combining technologies such as a large language model, artificial intelligence, machine learning, natural language processing (NLP) and the like. The security agent can monitor network behaviors in real time, automatically identify abnormal behaviors, generate security early warning and automatically execute a response strategy, so that the efficiency and accuracy of security operation are remarkably improved.
Owner:SHANDONG LANGCHAO YUNTOU INFORMATION TECH CO LTD