Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

343 results about "Network behavior" patented technology

Network behavior analysis (NBA) is a way to enhance the security of a proprietary network by monitoring traffic and noting unusual actions or departures from normal operation.

Backtracking analysis model construction method based on attack chain

The invention relates to the technical field of data processing, in particular to a backtracking analysis model construction method based on an attack chain, which comprises the following steps that: a kernel layer security agent acquires process, file and network behavior characteristics in a hardware isolation environment, and generates an event tuple; the tensor network pipeline performs three-dimensional decoupling mapping on the tuple into a behavior fingerprint vector, an orthogonalization noise feature and an asymmetric adjacent tensor, and compresses the behavior fingerprint vector, the orthogonalization noise feature and the asymmetric adjacent tensor into a space-time topology tensor block; the reinforcement learning controller constructs a directed acyclic graph based on the tensor blocks, calculates connectivity loss and outputs an event risk score; the dynamic routing engine constructs a decision tree model according to the risk mark, the burst frequency and the correlation entropy, and implements three-level shunting and a multiple simulation system to generate an anti-interference index; and when the deviation between the physical trajectory and the digital model exceeds the tolerance, the closed-loop feedback weight coefficient updates the loss function parameter and adjusts the channel resource weight. And the problem of threat discovery delay caused by attack chain breakage under massive events is solved.
Owner:HUANENG INFORMATION TECH CO LTD

Active Deep Learning Core with Locally Supervised Dynamic Pruning and Greedy Neurons

A computer system for adaptive operation of deep learning networks through hierarchical supervision, meta-level pattern tracking, cross-network signal coordination, and selective activation prioritization. The system operates a layered neural network monitored by a hierarchical supervisory system that collects activation data, identifies operational patterns, implements architectural modifications, detects network sparsity, coordinates pruning decisions, and manages resource redistribution. A meta-supervisory system tracks supervisory behavior, stores successful pruning and modification patterns, and extracts generalizable optimization principles. The system manages signal transmission pathways that enable direct communication between non-adjacent network regions, with signal modification and temporal coordination. A greedy neural system selectively processes activation patterns based on utility metrics and includes a competitive bidding manager to allocate limited computational resources to high-value signals. This architecture enables real-time optimization of network behavior and resource usage while maintaining operational stability and responsiveness across diverse applications.
Owner:ATOMBEAM TECH INC

Private network dynamic access control method and system

The invention discloses a private network dynamic access control method and system, and relates to the technical field of network security and access control. The method comprises the following steps: acquiring equipment behavior data and network flow data in a private network, performing feature construction, and generating equipment trust features and network behavior features; and carrying out multi-dimensional risk assessment model training based on the equipment trust features and the network behavior features, carrying out real-time risk assessment on access requests or entities in the private network through the trained multi-dimensional risk assessment model, and generating a real-time risk score through a weighted aggregation function. According to the invention, through the multi-modal feature fusion model based on an attention mechanism, deep association of static attributes and dynamic behavior features of equipment is realized, and a real-time risk score is generated in combination with a multi-dimensional risk assessment model and a weighted aggregation algorithm. The limitation that in traditional access control, the evaluation dimension is single, the static strategy lags behind, and dynamic threats cannot be reflected is effectively overcome, and the accuracy and interpretability of private network access risk perception are remarkably improved.
Owner:GUANGZHOU TRUSTMO INFORMATION SYST CO LTD

Heterogeneous event association representation model construction method, system and equipment based on attack stage semantic alignment

The invention provides a heterogeneous event association representation model construction method, system and device based on attack stage semantic alignment, and the method comprises the following steps: extracting six-tuple features from an obtained inter-host connection log, and obtaining inter-host alarm log data with unified representation; constructing an abnormal log fragment sequence between the hosts based on the alarm log data between the hosts; mapping the inter-host abnormal log fragment sequence to obtain an inter-host attack stage; eight-tuple features are extracted from the obtained operation logs in the hosts, and operation log data, represented in a unified mode, in the hosts are obtained; constructing a sensitive behavior log fragment sequence in the host based on the operation log data in the host; mapping the sensitive behavior log fragment mapping in the host to obtain an attack stage in the host; on the basis of semantic alignment of heterogeneous security events, associating an inter-host attack stage with an in-host attack stage according to topological features, and constructing a heterogeneous event association representation model; according to the method, an observation blind area existing in a single log source can be effectively overcome, network behaviors such as network scanning and vulnerability utilization and activities in a host such as script execution and permission promotion can be captured at the same time, and therefore more comprehensive and more complete restoration of the multi-step attack process is achieved.
Owner:XI AN JIAOTONG UNIV

Data filtering method and system for digital twin industrial control safety target range

The invention discloses a data filtering method and system for a digital twin industrial control safety target range. The method comprises the following steps: firstly, marking an IP address of an industrial control system network in a segmented manner; feature extraction is carried out on the network behavior data of each IP segment, and splicing is carried out on the IP segment label to serve as a feature sample for constructing an industrial control network security identification model; a plurality of inverted residual modules with the same structure are adopted as core construction units, network behavior features in the feature samples are extracted and learned, and classification training is carried out; deploying the trained industrial control network security identification model to a pre-filtering module of a digital twin industrial control security target range, and carrying out classification, identification and filtering on network behavior data flowing in each IP segment in real time; and the misjudged sample is subjected to backtracking analysis, and the IP marking rule is updated. According to the technical scheme, the accuracy of network behavior data identification can be improved, so that the effectiveness of industrial control system simulation is improved.
Owner:STATE GRID HENAN ELECTRIC POWER ELECTRIC POWER SCI RES INST +2

Cross-platform user behavior analysis method and system based on transfer learning

The invention provides a cross-platform user behavior analysis method and system based on transfer learning, and relates to the technical field of network security, first, historical network behavior record data of a source domain security platform and real-time network behavior flow data of a target domain security platform are obtained, the historical network behavior record data comprise security behavior sequences of source domain users in different access scenes, and the real-time network behavior flow data are stored in the target domain security platform; the method comprises the following steps of: performing cross-domain security feature extraction on two types of data, constructing a cross-domain security behavior association graph, migrating source domain historical malicious behavior mode knowledge to a target domain through a migration learning model based on the graph, generating cross-platform migration security features, and performing cross-domain security feature extraction on the target domain historical malicious behavior mode knowledge. And calling a security behavior analysis model to carry out joint modeling and time sequence security association analysis, identifying an abnormal security behavior mode of a target domain user, and finally matching a network security disposal rule base according to the abnormal mode, generating and issuing a protection strategy, and realizing real-time risk interception.
Owner:LESHAN NORMAL UNIV

Supplier behavior real-time sensing and monitoring method and device and electronic equipment

The invention relates to a supplier behavior real-time sensing and monitoring method and device and electronic equipment. The method comprises the steps of collecting and preprocessing supplier multi-source heterogeneous data in real time, dynamically capturing a Binlog of a MySQL database through a Flink CDC framework, obtaining service behavior data in real time, collecting text log data through a Flume framework, and transmitting network behavior data in real time. Integrating the structured data, the unstructured data and the semi-structured data, and constructing a unified data transmission channel; constructing a multi-dimensional user portrait; comparing the semantic similarity between the bidding file and the bidding requirement, and triggering compliance early warning when the matching degree is lower than a threshold value; analyzing a supplier cooperation network, and marking a cluster group with abnormal transaction frequency and irrelevant business fields as a cross-bidding risk; and analyzing the access behavior sequence, and detecting a malicious access pattern to generate a malicious access alarm. According to the supplier behavior monitoring system and method, real-time performance, accuracy and multidimensional performance of supplier behavior monitoring are achieved through the architecture of multi-source heterogeneous data real-time integration, multi-dimensional portrait construction and intelligent risk identification.
Owner:CHINA ACADEMY OF RAILWAY SCI CORP LTD +1

Intelligent influenza early warning system based on community multi-modal data fusion

The invention relates to the technical field of infectious disease monitoring and early warning, and discloses an intelligent influenza early warning system based on community multi-modal data fusion. The community-level multi-modal data fusion architecture is constructed, medical health data, environmental data, crowd activity data and network behavior data are integrated, spatial-temporal features are dynamically extracted and fused in combination with a deep learning model, and the problem of community monitoring blind areas caused by a single data source of an existing early warning system is solved; a long short-term memory network and convolutional neural network cascade architecture is utilized to capture a localized propagation rule, and the defect that a region-level prediction model cannot adapt to community heterogeneity is overcome; the risk score is generated in real time, the grading response instruction is triggered, a'monitoring-early warning-intervention 'closed loop is established, the early warning timeliness is remarkably improved, a basic-level response chain scission gap is filled, early prevention and control of flu outbreak are finally achieved, and public health resource consumption is reduced.
Owner:武之琳

Network access control system and method and related equipment

The invention relates to a network access control system, a network access control method and related equipment. In the system, a client agent module is used for acquiring process identification information and establishing a binding relationship between a process and a network message; the traffic acquisition and analysis module is used for acquiring network messages at a gateway side, analyzing and aggregating the network messages and generating a structured traffic record; the process association verification module is used for verifying the validity of the binding relationship and establishing and maintaining the association relationship between the process and the structured traffic record; the traffic aggregation and strategy generation module is used for executing traffic aggregation and network behavior analysis based on the structured traffic record and the association relationship, and dynamically generating an access control strategy based on a network behavior analysis result; and the dynamic access control execution module is used for controlling the network access request based on the access control strategy and generating an execution result containing the control result. The system realizes self-adaptive generation of process-level control and access control strategies.
Owner:BEIJING EETRUST TECH CO LTD

Magnetic anomaly data de-noising method and de-noising system based on step-by-step U-Net

The invention discloses a magnetic anomaly data de-noising method and de-noising system based on step-by-step U-Net, and relates to the technical field of geophysical exploration, and the method comprises the steps: carrying out the forward modeling calculation based on a magnetic anomaly model in a simulation region, and obtaining a synthetic magnetic anomaly data set; a U-Net step-by-step denoising network model is constructed; designing a self-adaptive multi-stage training mechanism based on mean square error minimization; training the U-Net step-by-step denoising network model through the training set, taking parameters of the U-Net step-by-step denoising network model as initial weights, and performing fine tuning on the U-Net step-by-step denoising network model by utilizing supervised learning; the verification set is used for verifying the effect, and the effectiveness of the whole step-by-step denoising network model is verified according to the prediction effect of the test set; a forward noise adding process and a reverse noise removing process are designed, network behaviors are automatically adjusted according to noise steps, the problems of high training cost and poor performance when a deep learning model processes colored noise are effectively solved, and the problem of low signal-to-noise ratio is better solved.
Owner:JILIN UNIVERSITY

Multi-source threat detection method based on hybrid expert model

According to the multi-source threat detection method based on the hybrid expert model, real-time collection and structured processing of network flow, system logs and user behavior data are achieved through a multi-mode intelligent collection engine, and high-quality multi-source input is provided for upper-layer analysis; the double-branch feature extractor carries out deep analysis on the network flow time sequence mode and the log semantic context to generate fine-grained feature vectors; the hybrid expert reasoning framework is based on expert models in three fields of a dynamic routing gating network, intelligent scheduling network behaviors, log semantics and user portraits, combines space-time alignment features through a cross-modal attention mechanism, and constructs an interpretable attack evidence chain in combination with a causal reasoning engine. Finally, a full-link closed loop from multi-modal data acquisition, feature collaborative extraction and intelligent threat reasoning is realized, and while millisecond-level real-time response is ensured, the complex internal threat detection accuracy is obviously improved.
Owner:THE QUARTERMASTER RES INST OF THE GENERAL LOGISTICS DEPT OF THE CPLA

Cybersecurity Analysis and Protection Using Distributed Systems

Cybersecurity reconnaissance, analysis, and scoring uses distributed, cloud or edge-based pools of computing services to provide sufficient scalability for analysis of IT / OT networks using only publicly available characterizations. An in-memory associative array manages a queue of configuration and vulnerability search tasks through at least one public-facing proxy network which uses configurable search nodes to approach the target network with search tools in a desired manner to control certain aspects of the search in order to obtain the desired results, especially when target network behavior adjusts based on counterparty characteristics. A data packet modifier reveals IP addresses of threat actors behind port scans and subsequently block the threat actors.
Owner:QPX LLC

Pathogen transmission rapid early warning and traceability analysis method based on multi-source data fusion

The invention discloses a pathogen transmission rapid early warning and traceability analysis method based on multi-source data fusion. The method comprises the steps of S1, collecting multi-source data such as drug sales, network behaviors, social media, outpatient diagnosis and traffic time and space; s2, through cleaning and standardized preprocessing, social text disease features are extracted by adopting BERT; s3, mining a comprehensive weak signal through single-source anomaly detection and multi-source correlation analysis; s4, fusing the features by using an Attention-LSTM model, and outputting a regional risk index; s5, training an early warning model based on historical data, and setting a three-level threshold to trigger early warning; and S6, positioning a propagation starting point in combination with the spatio-temporal data, and constructing a propagation chain through a graph neural network. The early warning is advanced by 3-7 days, the traceability precision reaches the community level, and the prevention and control precision is improved.
Owner:SHANGHAI XUHUI DISTRICT CENT FOR DISEASE CONTROL & PREVENTION (SHANGHAI XUHUI DISTRICT PATRIOTIC HEALTH & HEALTH PROMOTION CENT)

EBPF-based adaptive probe deployment and distributed context tracking method, system and device, and storage medium

PendingCN121277785AHardware monitoringShardProbe type
The invention relates to the technical field of cloud native monitoring, in particular to an eBPF-based adaptive probe deployment and distributed context tracking method, system and device and a storage medium. Performing static analysis and dynamic monitoring on a target application through an adaptive probe scheduler, constructing a function criticality scoring model, intelligently selecting a probe type and deploying the probe type to a key function; the method comprises the following steps: capturing a distributed tracking identifier by applying a semantic probe, analyzing application layer data, performing desensitization processing, and injecting an anchor point context into kernel mode storage; establishing a context transfer mechanism based on the process group identifier, monitoring cross-service calling through a network connection hook probe, and realizing deterministic association transfer by using a socket identifier; and performing multi-level context fusion through a network behavior probe, and associating the network behavior with the application context in real time to generate complete call chain information. According to the method, the problems of static fragility and context fragmentation of probe deployment in a cloud native environment are solved, and self-adaptive end-to-end full link tracking is realized.
Owner:GUANGDONG POWER GRID CO LTD INFORMATION CENT

Systems and methods for multicast data traffic service continuity under multicast-broadcast services operation during radio resource control state transition

Systems and methods for multicast data traffic service continuity under multicast-broadcast services (MBS) operation during a radio resource control (RRC) state or mode transition are described. In some embodiments, a user equipment (UE) receives, from a network, while in an RRC connected mode, an RRC release message comprising an RRC inactive mode point to multipoint (PTM) configuration that uses an MBS session to receive multicast data traffic while the UE is in an RRC inactive mode; enters the RRC inactive mode from the RRC connected mode in response to the RRC release message; and uses the RRC inactive mode PTM configuration to receive, from the network, the multicast data traffic of the MBS session while the UE is in the RRC inactive mode. Cases where a UE instead re-uses an RRC connected mode PTM configuration after transitioning to the RRC inactive mode are also described. Analogous network behaviors are described.
Owner:APPLE INC

Digital twin enablers for open radio access networks

A digital twin of a wireless network comprises a registry storing services supported by digital twin functions; a 3D model management function for selecting a model; a network topology model management function for selecting a site and hardware; and a UE profile model management function for selecting user device distribution and mobility, and traffic profiles. The digital twin also includes a radio model management function for selecting and generating a radio model; a network and UE model management function for providing network behavior models and UE behavior models for running simulations; and a configuration model management function for selecting and creating network configurations and UE configurations for multiple modules. The digital twin further includes a simulation services module for simulating network and UE behavior; and a simulation orchestrator function for planning, analyzing, and optimizing network features and scenarios.
Owner:QUALCOMM INC

User equipment (UE) and access mobility management function (AMF)

To clarify an efficient control method related to an unavailability period, and UE behavior and network behavior associated with the unavailability period. In a case of updating the unavailability period while a timer using the unavailability period is running, a UE updates the stored unavailability period, stops the timer, and starts the timer by using the updated unavailability period.
Owner:SHARP KK

System and method for identifying anomalous network threat events that occur in a private computer network

ActiveUS12432238B1Securing communicationSliding time windowNetwork behavior
Network threat events are declared in response to detecting network traffic data indicative of network threats in network traffic involving hosts of a private computer network. Common hosts of the private computer network are identified in network threat events that have occurred within a sampling period. For each identified common host, a baseline of network behavior of the common host in network threat events that have occurred within a sliding time window is generated. A new threat event that has occurred after the sliding time window is identified as anomalous by comparing a network behavior of a common host in the new network threat event against the baseline of network behavior of the common host. An alert is issued in response to detecting an anomalous network threat event that has a risk rating that exceeds a threshold risk level.
Owner:TREND MICRO INC

Network information security protection method and system

The invention relates to the technical field of network information security, and discloses a network information security protection method and system, and the method comprises the following steps: S1, constructing and initializing a dynamic threat matrix, taking an entity in a network as a row dimension, and taking the behavior characteristics of the entity as a column dimension to form a matrix framework, calculating a behavior baseline entropy value based on historical normal behavior data of each entity in each feature dimension, filling the behavior baseline entropy value into a corresponding position of a matrix to complete initialization, and setting an entropy threshold value for each element; s2, collecting real-time behavior data of each entity, and calculating a real-time entropy value; according to the method, the dynamic threat matrix is constructed, the uncertainty of entity behaviors is quantified by using information entropy, and the abnormal change of network behaviors is sensed in real time by combining a sliding window mechanism and a multi-factor weighted fusion algorithm, so that the limitation of traditional static threshold detection is broken through, the rule base updating hysteresis is eliminated, and novel attack behavior characteristics can be captured; the high-entropy regional distribution of the matrix can provide a quantitative basis for risk positioning.
Owner:ZHENGZHOU RAILWAY VOCATIONAL & TECH COLLEGE

A Cross-Platform User Behavior Analysis Method and System Based on Transfer Learning

This invention provides a cross-platform user behavior analysis method and system based on transfer learning, relating to the field of network security technology. First, it acquires historical network behavior records from a source domain security platform and real-time network behavior stream data from a target domain security platform. The former includes security behavior sequences of source domain users under different access scenarios, while the latter includes dynamic security operation records of the target domain user's current session. Next, it extracts cross-domain security features from both types of data to construct a cross-domain security behavior association graph. Based on this graph, it uses a transfer learning model to transfer historical malicious behavior patterns from the source domain to the target domain, generating cross-platform transferred security features. Then, it calls a security behavior analysis model for joint modeling and temporal security association analysis to identify abnormal security behavior patterns of target domain users. Finally, it matches the abnormal patterns with a network security handling rule base to generate and distribute protection policies, achieving real-time risk interception.
Owner:LESHAN NORMAL UNIV

Network data security and privacy protection method and device

The invention discloses a network data security and privacy protection method and device, and the method comprises the steps: obtaining network behavior data features in real time, calculating a behavior entropy value, judging whether to trigger privacy protection or not based on the behavior entropy value, and continuing a next step if the privacy protection is triggered; dynamic privacy budgets of different features are generated based on the behavior entropy in combination with an LSTM model; generating a feature sensitivity grade through a dynamic privacy budget; performing mask processing on the gradient network behaviors of the corresponding features based on feature sensitivity classification; the main technical scheme and effects are as follows: 1, through a dynamic privacy quantification engine, a network behavior entropy value is calculated in real time, and a risk is predicted by using an LSTM model, so that a dynamically changing privacy budget is generated; in this way, the privacy protection intensity can be adaptively adjusted according to the real-time threat situation, and the rigid mode of fixed budget in the existing differential privacy technology is thoroughly broken through.
Owner:GUANGXI POWER GRID CORP

Biological characteristic intelligent management system and method based on artificial intelligence

The invention relates to the technical field of information management, and discloses a biological characteristic intelligent management system and method based on artificial intelligence, and the method comprises the following steps: responding to a business request initiated by a user, and collecting at least two kinds of biological characteristic information of the user; inputting the biological characteristic information into a pre-trained multi-modal fusion model to generate a composite biological characteristic code; wherein the multi-modal fusion model adopts an attention mechanism to dynamically weight and fuse contribution degrees of different biological characteristics; and based on the context information of the service request, the hardware fingerprint of the user terminal and the current network behavior mode. According to the method, multi-modal biological feature fusion and dynamic risk assessment are combined, the accuracy and reliability of an identity authentication system are remarkably improved, different biological features are adaptively weighted by using an attention mechanism, the distinction degree and the anti-counterfeiting capability of a composite feature code are effectively enhanced, and the security of the identity authentication system is improved. Therefore, the user identity can be discriminated more accurately in a complex application scene.
Owner:GUANGDONG QILI ELECTRONICS CO LTD

Method and system for identifying abnormal network behavior of intranet terminal

The invention discloses an intranet terminal abnormal network behavior identification method and system, and the method comprises the steps: capturing network flow, extracting multi-dimensional heterogeneous features, and obtaining a feature embedding vector set through vectorization coding and IP segmentation embedding processing; constructing a semantic-space mapping mechanism between features, converting a logic neighborhood relationship in a network protocol into an Euclidean space neighborhood relationship in a pseudo-spatial feature grid, and stacking along a time dimension to generate a four-dimensional feature topology tensor; respectively extracting local correlation, axis distribution and long-distance dependence characteristics by using squares, bars and expansion convolution kernels which are arranged in parallel, and carrying out self-adaptive weighted fusion; and finally, based on the fusion feature vector, determining abnormity through a full-connection classification layer. According to the method, the discrete traffic data is converted into the pseudo-space tensor with semantic topology, so that the logic structure of network behaviors is effectively recovered, and the recognition precision of hidden attacks in an internal network and an industrial control environment is remarkably improved in cooperation with multi-scale convolution.
Owner:YINCHUAN POWER SUPPLY COMPANY OF STATE GRID NINGXIA ELECTRIC POWER

Mobile application security detection method and system based on multi-dimensional features and network behavior fingerprints

The invention provides a mobile application security detection method and system based on multi-dimensional features and network behavior fingerprints, and relates to the technical field of network security, the method comprises the following steps: running a mobile application in a controlled environment, capturing network traffic data generated in the running process of the mobile application, extracting dynamic behavior characteristics including communication frequency, communication type and communication content from the network flow data, constructing a network behavior fingerprint based on the dynamic behavior characteristics, and performing normalization processing on the dynamic behavior characteristics to obtain normalized dynamic behavior characteristics; and in combination with a risk classification threshold and the normalized dynamic behavior characteristics, correcting a scoring result to obtain a final security score. According to the method, the static code layer features and the dynamic flow layer features are comprehensively analyzed, the mobile application type is judged, and efficient traceability is achieved.
Owner:HARBIN INST OF TECH AT WEIHAI +1

Industrial network security situation prediction method and system based on generative large model

The invention provides an industrial network security situation prediction method and system based on a generative large model, and relates to the technical field of industrial network security, and the method comprises the steps: obtaining time sequence network behavior data of a plurality of monitoring nodes in an industrial network, and extracting multi-dimensional features to obtain a security feature vector; decomposing the feature vector into a periodic baseline component and a transient disturbance component through frequency domain transformation, and obtaining a decomposition situation feature through sparsity constraint screening; performing semantic space mapping by utilizing a generative large model to obtain semantic enhanced situation representation, calculating security anomaly correlation between nodes based on decomposed situation characteristics, and constructing a dynamic incidence matrix; and constructing a propagation operator based on the dynamic incidence matrix, carrying out multi-step iterative propagation on the semantic enhancement situation representation, introducing an attenuation factor to simulate abnormal influence diffusion, and obtaining a security situation prediction result in a future time window.
Owner:NAT IND INFORMATION SECURITY DEV RES CENT

Network security data management system and method based on AI large model

The invention belongs to the technical field of data security management, and discloses a network security data management system and method based on an AI large model, and the method comprises the steps: obtaining historical network behavior data and corresponding time information and network environment data, carrying out the characterization processing of the network behavior data in different time periods, and obtaining a network behavior data feature; obtaining network security features and forming a historical database; training the baseline model to predict network security features; acquiring real-time time information and network environment data, and acquiring expected and current actual network security features; comparing the current network security feature with an expected network security feature, and generating a risk assessment result; and dynamically adjusting a data access control and encryption strategy according to a risk assessment result. According to the method, by predicting normal network behaviors and comparing the normal network behaviors with actual behaviors, security threats can be accurately identified, the security policy is adaptively adjusted according to the risk level, and the balance of security and availability is realized.
Owner:ZHONGCHENG AUTO INSURANCE CO LTD

Communication method and apparatus

This application relates to the field of communication technologies, and provides a communication method and apparatus. The method includes: A first network device sends at least one reference signal to a second network device, to receive a measurement result of the second network device on the at least one reference signal; and the first network device determines, based on the measurement result, at least one resource for communication with at least one terminal device. According to the method, the first network device determines, by using the measurement result of the second network device on the reference signal, the resource used for communication between the first network device and the terminal device, thereby coordinating network behaviors of different network devices, avoiding a conflict between resources used by different network devices, improving network reliability, and improving communication performance.
Owner:HUAWEI TECH CO LTD

Network security monitoring method

The invention discloses a network security monitoring method, which comprises the following steps of: acquiring full-life-cycle data and attributes of network processes in real time, constructing a process chain table and an associated network, and sorting a relationship between the processes; secondly, matching a network event with a process timeline, dynamically dividing a time window according to a process life cycle, calculating a process time characteristic and a network activity characteristic, comparing a historical normal mode, quantifying a difference by utilizing an algorithm, and identifying an abnormal process; then, inputting the comparison process into a support vector machine to establish a prediction model, and predicting an abnormal process in real time; and finally, abnormal process information is fed back to the security equipment, and abnormal files are positioned and isolation / deletion operation is executed in combination with network behavior data association analysis. According to the method, the abnormal process can be accurately identified, misjudgment is reduced, the sensitivity requirements of different service scenes are met, the abnormal file is positioned by means of network behaviors, and the accuracy and timeliness of network security protection are effectively improved.
Owner:GUIZHOU BLUESKY INNOVATIVE SCI & TECH CO LTD

Network-based electromechanical equipment operating system and method

The invention discloses a network-based electromechanical equipment operating system and method. The system comprises the following units: a data preprocessing unit, a model construction unit, a weight adjustment unit, a state diagnosis unit and an operation guidance unit. The data preprocessing unit is used for acquiring and preprocessing three-source original data of the machine room heating and cooling control equipment, and the three-source original data comprises physical signal related data, network behavior related data and operation log related data; the invention relates to the technical field of electromechanical equipment management. According to the electromechanical equipment operating system and method based on the network, by monitoring the deviation between the health index of the heating and cooling control equipment in the machine room and the historical health track, early warning can be automatically triggered and weight migration can be executed when the deviation exceeds the set threshold value, real-time monitoring and early warning of the equipment state can be achieved, potential fault risks can be found in time, and the reliability of the system is improved. And the equipment fault occurrence probability is effectively reduced.
Owner:SHAANXI DATANG GAOKE ELECTROMECHANICAL TECH CO LTD