Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

203 results about "Network behavior" patented technology

Network behavior analysis (NBA) is a way to enhance the security of a proprietary network by monitoring traffic and noting unusual actions or departures from normal operation.

Network access control system and method and related equipment

The invention relates to a network access control system, a network access control method and related equipment. In the system, a client agent module is used for acquiring process identification information and establishing a binding relationship between a process and a network message; the traffic acquisition and analysis module is used for acquiring network messages at a gateway side, analyzing and aggregating the network messages and generating a structured traffic record; the process association verification module is used for verifying the validity of the binding relationship and establishing and maintaining the association relationship between the process and the structured traffic record; the traffic aggregation and strategy generation module is used for executing traffic aggregation and network behavior analysis based on the structured traffic record and the association relationship, and dynamically generating an access control strategy based on a network behavior analysis result; and the dynamic access control execution module is used for controlling the network access request based on the access control strategy and generating an execution result containing the control result. The system realizes self-adaptive generation of process-level control and access control strategies.
Owner:BEIJING EETRUST TECH CO LTD

Multi-source threat detection method based on hybrid expert model

According to the multi-source threat detection method based on the hybrid expert model, real-time collection and structured processing of network flow, system logs and user behavior data are achieved through a multi-mode intelligent collection engine, and high-quality multi-source input is provided for upper-layer analysis; the double-branch feature extractor carries out deep analysis on the network flow time sequence mode and the log semantic context to generate fine-grained feature vectors; the hybrid expert reasoning framework is based on expert models in three fields of a dynamic routing gating network, intelligent scheduling network behaviors, log semantics and user portraits, combines space-time alignment features through a cross-modal attention mechanism, and constructs an interpretable attack evidence chain in combination with a causal reasoning engine. Finally, a full-link closed loop from multi-modal data acquisition, feature collaborative extraction and intelligent threat reasoning is realized, and while millisecond-level real-time response is ensured, the complex internal threat detection accuracy is obviously improved.
Owner:THE QUARTERMASTER RES INST OF THE GENERAL LOGISTICS DEPT OF THE CPLA

Pathogen transmission rapid early warning and traceability analysis method based on multi-source data fusion

The invention discloses a pathogen transmission rapid early warning and traceability analysis method based on multi-source data fusion. The method comprises the steps of S1, collecting multi-source data such as drug sales, network behaviors, social media, outpatient diagnosis and traffic time and space; s2, through cleaning and standardized preprocessing, social text disease features are extracted by adopting BERT; s3, mining a comprehensive weak signal through single-source anomaly detection and multi-source correlation analysis; s4, fusing the features by using an Attention-LSTM model, and outputting a regional risk index; s5, training an early warning model based on historical data, and setting a three-level threshold to trigger early warning; and S6, positioning a propagation starting point in combination with the spatio-temporal data, and constructing a propagation chain through a graph neural network. The early warning is advanced by 3-7 days, the traceability precision reaches the community level, and the prevention and control precision is improved.
Owner:SHANGHAI XUHUI DISTRICT CENT FOR DISEASE CONTROL & PREVENTION (SHANGHAI XUHUI DISTRICT PATRIOTIC HEALTH & HEALTH PROMOTION CENT)

Method and system for identifying abnormal network behavior of intranet terminal

The invention discloses an intranet terminal abnormal network behavior identification method and system, and the method comprises the steps: capturing network flow, extracting multi-dimensional heterogeneous features, and obtaining a feature embedding vector set through vectorization coding and IP segmentation embedding processing; constructing a semantic-space mapping mechanism between features, converting a logic neighborhood relationship in a network protocol into an Euclidean space neighborhood relationship in a pseudo-spatial feature grid, and stacking along a time dimension to generate a four-dimensional feature topology tensor; respectively extracting local correlation, axis distribution and long-distance dependence characteristics by using squares, bars and expansion convolution kernels which are arranged in parallel, and carrying out self-adaptive weighted fusion; and finally, based on the fusion feature vector, determining abnormity through a full-connection classification layer. According to the method, the discrete traffic data is converted into the pseudo-space tensor with semantic topology, so that the logic structure of network behaviors is effectively recovered, and the recognition precision of hidden attacks in an internal network and an industrial control environment is remarkably improved in cooperation with multi-scale convolution.
Owner:YINCHUAN POWER SUPPLY COMPANY OF STATE GRID NINGXIA ELECTRIC POWER

Industrial network security situation prediction method and system based on generative large model

The invention provides an industrial network security situation prediction method and system based on a generative large model, and relates to the technical field of industrial network security, and the method comprises the steps: obtaining time sequence network behavior data of a plurality of monitoring nodes in an industrial network, and extracting multi-dimensional features to obtain a security feature vector; decomposing the feature vector into a periodic baseline component and a transient disturbance component through frequency domain transformation, and obtaining a decomposition situation feature through sparsity constraint screening; performing semantic space mapping by utilizing a generative large model to obtain semantic enhanced situation representation, calculating security anomaly correlation between nodes based on decomposed situation characteristics, and constructing a dynamic incidence matrix; and constructing a propagation operator based on the dynamic incidence matrix, carrying out multi-step iterative propagation on the semantic enhancement situation representation, introducing an attenuation factor to simulate abnormal influence diffusion, and obtaining a security situation prediction result in a future time window.
Owner:NAT IND INFORMATION SECURITY DEV RES CENT

Network security monitoring method

The invention discloses a network security monitoring method, which comprises the following steps of: acquiring full-life-cycle data and attributes of network processes in real time, constructing a process chain table and an associated network, and sorting a relationship between the processes; secondly, matching a network event with a process timeline, dynamically dividing a time window according to a process life cycle, calculating a process time characteristic and a network activity characteristic, comparing a historical normal mode, quantifying a difference by utilizing an algorithm, and identifying an abnormal process; then, inputting the comparison process into a support vector machine to establish a prediction model, and predicting an abnormal process in real time; and finally, abnormal process information is fed back to the security equipment, and abnormal files are positioned and isolation / deletion operation is executed in combination with network behavior data association analysis. According to the method, the abnormal process can be accurately identified, misjudgment is reduced, the sensitivity requirements of different service scenes are met, the abnormal file is positioned by means of network behaviors, and the accuracy and timeliness of network security protection are effectively improved.
Owner:GUIZHOU BLUESKY INNOVATIVE SCI & TECH CO LTD

Network-based electromechanical equipment operating system and method

The invention discloses a network-based electromechanical equipment operating system and method. The system comprises the following units: a data preprocessing unit, a model construction unit, a weight adjustment unit, a state diagnosis unit and an operation guidance unit. The data preprocessing unit is used for acquiring and preprocessing three-source original data of the machine room heating and cooling control equipment, and the three-source original data comprises physical signal related data, network behavior related data and operation log related data; the invention relates to the technical field of electromechanical equipment management. According to the electromechanical equipment operating system and method based on the network, by monitoring the deviation between the health index of the heating and cooling control equipment in the machine room and the historical health track, early warning can be automatically triggered and weight migration can be executed when the deviation exceeds the set threshold value, real-time monitoring and early warning of the equipment state can be achieved, potential fault risks can be found in time, and the reliability of the system is improved. And the equipment fault occurrence probability is effectively reduced.
Owner:SHAANXI DATANG GAOKE ELECTROMECHANICAL TECH CO LTD

A Batch Multimodal Data Alignment Method and System Based on CLIP Model

This invention discloses a batch multimodal data alignment method and system based on the CLIP model, belonging to the field of information processing technology. The method includes: S1: receiving batch multimodal data; S2: data preprocessing; S3: batch feature extraction based on the CLIP model to achieve feature alignment; S4: batch classification based on a Prompt template; S5: result generation and output, and visualization processing. This invention is applicable to user behavior analysis, abnormal traffic detection, and network content security governance in a big data communication environment. It fully utilizes CLIP's powerful cross-modal semantic alignment and zero-sample transfer capabilities, combined with batch optimization strategies, dynamic task scheduling, and a batch classification method based on a Prompt template, thereby achieving efficient, flexible, and scalable multimodal data processing, accurately identifying malicious text, malicious images, and cross-modal risk links, and enabling real-time monitoring and intelligent prevention of malicious network behavior.
Owner:NANJING UNIV OF SCI & TECH

Network anomaly root cause positioning method, storage medium and computer program product

The invention provides a network abnormal root cause positioning method, a storage medium and a computer program product, and further determines a state space based on time sequence format data by determining a time sequence format of a detection point data set. Therefore, on the basis of the time sequence format data and the state space, index parameters for evaluating the network behavior chaos condition of the detection points are determined. Therefore, early recognition can be carried out before the network exception develops to a serious stage. Meanwhile, root cause analysis is performed in combination with the abnormal root cause prediction model, so that the recognition of complex network behaviors can be improved, and the root of network anomaly can be more accurately positioned.
Owner:LIAONING MOBILE COMM +1

Network traffic map data processing method and system for digital services

The embodiment of the application provides a network traffic map data processing method and system applied to digital services, determines a target network traffic map sequence and a network behavior mining node sequence corresponding to each target network traffic map in the target network traffic map sequence, obtains an initial node change instruction corresponding to the target network traffic map sequence, determines a changed network traffic map sequence corresponding to the target network traffic map sequence according to the initial node change instruction, obtains a first model scheduling distinguishing parameter corresponding to the changed network traffic map sequence, obtains a second model scheduling distinguishing parameter corresponding to the changed network traffic map sequence, determines a target change instruction according to the first model scheduling distinguishing parameter and the second model scheduling distinguishing parameter corresponding to each initial node change instruction, and changes the network behavior mining node in the target network traffic map sequence according to the target change instruction, thereby improving the feature mining reliability of the network traffic map.
Owner:HANGYIN CONSUMER FINANCE CO LTD

An intelligent detection method for network abnormal behavior

This invention proposes an intelligent method for detecting abnormal network behavior, including acquiring target network traffic data, constructing a multi-dimensional feature fusion model based on an attention mechanism, and building an abnormal behavior classification model based on deep learning. By automatically allocating attention to different network traffic features through the attention mechanism, it solves the problems of unreasonable feature weight allocation and insufficient feature fusion in traditional methods, significantly improving the detection capability for low-frequency and covert abnormal behaviors and effectively reducing false positive and false negative rates. The classification model employs a hybrid CNN and LSTM structure, taking into account both the local spatial and temporal features of network traffic, and can accurately identify various types of abnormal network behaviors such as DDoS attacks, port scanning, SQL injection, and malicious code propagation, adapting to diverse attack scenarios with high classification accuracy.
Owner:SHIJIAZHUANG ANJIE FUTURE TECHNOLOGY CO LTD

An app-assisted remote Internet of Things terminal black box fuzzing method

The application provides an App-assisted remote Internet of Things terminal black box fuzzy test method, which comprises the following steps: extracting an App control command based on a document; identifying a mutation point based on App hybrid analysis; conducting fuzzy test based on side channel information guidance; and monitoring an Internet of Things terminal crash based on network behavior. The application uses the time interval between the sending and receiving responses of network messages as side channel information to infer the server-side black box verification logic, realizes the Internet of Things terminal black box fuzzy test technology supported by the bypass cloud server, and thus automatically mines the vulnerabilities of the Internet of Things terminal remotely. The application effectively solves the challenge of remote Internet of Things device black box fuzzy test and improves the fuzzy test efficiency.
Owner:SOUTHEAST UNIV

Combinable core particle network-oriented period precision simulator design method

The invention discloses a period precise simulator design method for a combinable core particle network, and relates to the technical field of core simulation testing, and the method comprises the steps: designing a simulation frame of a combinable core particle network simulator; wherein the simulation framework comprises a two-stage core particle network configuration unit and a multi-thread parallel simulation framework; carrying out combinable topology modeling, modular routing mechanism modeling and heterogeneous router micro-architecture modeling on the combinable core particle network; performing protocol layer protocol conversion modeling, protocol layer flow control mechanism modeling, adaptation layer retransmission mechanism modeling and physical layer electrical behavior modeling on the core particle interconnection protocol interface; based on the above design, the period precision simulator for the combinable core particle network is constructed. By designing the simulation framework, more accurate actual core particle network behaviors can be obtained; a higher simulation speed is realized through a multi-thread parallel simulation framework, multi-thread parallel accelerated simulation under a large-scale network is supported, and the simulation test efficiency is improved.
Owner:SUN YAT SEN UNIV

A method and system for real-time monitoring and early warning of unauthorized external connections based on deep learning

This invention discloses a method and system for real-time monitoring and early warning of unauthorized external connections based on deep learning, comprising the following modules: a data acquisition and dynamic graph construction module for real-time acquisition of external connection behavior data and generation of a dynamic graph structure; an event monitoring and local subgraph identification module for monitoring node and edge changes and identifying relevant local subgraphs; an incremental dynamic graph neural network training module for parameter updates and feature propagation within the local subgraph; a group attention feature aggregation module for feature aggregation under a multi-granularity attention mechanism; a graph attention decision classification module for classification and risk determination based on anomaly information entropy; and a global asynchronous aggregation and early warning output module for aggregating and outputting early warning information across the entire network. This invention can efficiently integrate multi-source network behavior and contextual features to achieve accurate real-time monitoring and intelligent early warning of unauthorized external connections in complex network environments.
Owner:JIANGXI ZHUNYUN INTELLIGENT TECH CO LTD

A method and system for identifying power access device anomalies by fusing feature deviation and temporal constraints

The application discloses a power access equipment anomaly identification method fusing feature deviation and timing constraints, which solves the problem that detection accuracy and real-time performance are difficult to be considered together under the condition of limited edge computing power by constructing a device-side network behavior digital twin on the edge proxy device in the power cloud edge system. Specifically, the method calculates the feature deviation between the actual behavior and the expected behavior; at the same time, the relative time difference-based service timing constraint is introduced. By fusing the feature deviation and the timing violation degree, the application can identify the abnormal behavior of malicious access equipment or attacked equipment in real time at the edge, and perform instant blocking and session control on the main service path, so as to realize the identification ability of high accuracy, high real-time and sustainable evolution of the abnormal behavior of the access layer equipment under the premise of meeting the real-time performance and safety compliance requirements of the power system.
Owner:HUNAN KUANGAN NETWORK TECH CO LTD

A network behavior security early warning method and system

This invention provides a network behavior security early warning method and system, relating to the field of network security technology. The method includes: acquiring attack event data; preprocessing and clustering the attack event data to obtain a first clustering result; acquiring a first key feature of network behavior corresponding to attack events in the same cluster, constructing a network abnormal behavior feature set; predicting subsequent network behavior based on a prediction model; determining the risk value of the predicted subsequent network behavior based on network behavior association principles; when the risk value is not less than a first preset threshold, collecting a second key feature from the predicted subsequent network behavior features; performing feature matching between the second key feature and the network abnormal behavior feature set; determining whether the predicted subsequent behavior will face an attack event based on the matching degree; and issuing a security early warning. By analyzing attack event data and predicting subsequent network behavior, the risk value of subsequent network behavior being attacked is determined, thus achieving a security early warning.
Owner:SHENZHEN XINGHUO ELECTRONIC ENG CO +1

User equipment and network behavior with restricted satellite access by subscription in mobile communications

Examples pertaining to user equipment (UE) and network behavior with restricted satellite access by subscription in mobile communications are described. A user equipment (UE) receives from a satellite access cell of a network a message with a reject cause. The UE then either or both refrains to attempt the satellite access and disables the satellite access capability of the UE responsive to receiving the message.
Owner:MEDIATEK SINGAPORE PTE LTD

Server access detection method and device, electronic equipment and storage medium

The embodiment of the invention provides a server access detection method and device, electronic equipment and a storage medium, belongs to the technical field of network security, and is applied to the field of financial science and technology and the field of health medical treatment. The method comprises the following steps: performing feature extraction on a network connection log to obtain a network behavior time sequence feature, a log semantic feature and a network behavior topological feature; performing pattern recognition according to the network behavior time sequence features, the log semantic features and the network behavior topological features to obtain a network behavior pattern; constructing a network topological graph according to the source address, the target address, the first sub-network segment and the second sub-network segment, wherein the network topological graph comprises network nodes; performing feature extraction on the network topological graph to obtain node embedding features of network nodes; and performing access detection on the server according to the network behavior pattern and the node embedding feature to obtain an access category, the access category including normal access or abnormal access. According to the embodiment of the invention, the accuracy of server access detection can be improved.
Owner:PING AN TECH (SHENZHEN) CO LTD

Network security protection system and method

The invention relates to the technical field of network security, in particular to a network security protection system and method. The system comprises an original flow data acquisition module, a metadata generation module, a data storage management module, a data feature extraction module, a feature vector anomaly detection module, a threat alarm analysis module and a threat alarm response execution module which are connected in sequence. According to the method, through full-flow capture and deep metadata analysis, a complete and uniform network behavior view is constructed, and the threat discovery and perception capability is remarkably improved. Unsupervised anomaly detection is carried out by using a deep learning model such as an auto-encoder, a normal network behavior mode can be adaptively learned, unknown threats and variant attacks are effectively identified, and the false alarm rate is reduced. The risk assessment is performed by fusing the multi-source data, and the response instruction is automatically generated and executed based on the assessment result, so that the closed-loop automatic disposal of the security event is realized, the response time is greatly shortened, and the dependence on manual intervention is reduced.
Owner:河源市人民医院

Transaction network behavior map dynamic early warning system

A transaction network behavior graph dynamic early warning system comprises a heterogeneous graph Transformer module used for extensible static graph embedding and a dynamic updater used for executing lightweight incremental graph embedding model decoupling, so that when node attributes are missing, the model can seamlessly return to a pure ID embedding mode in the training and inference process. In a static graph training stage, time complexity and memory occupation are realized, and a large-scale heterogeneous graph with billion-level nodes and edges can be expanded. In the incremental updating stage, a single-step matrix decomposition method is adopted to replace traditional gradient descent based on back propagation, the complete iterative optimization process of the model is avoided, and meanwhile the method is suitable for the production environment where GPU resources are limited or unavailable. The method does not depend on any special hardware for acceleration, can be executed on a common server CPU, and ensures real-time response and model updating of a dynamic interaction event.
Owner:SHANGHAI JIAOTONG UNIV

Mobile phone signal detection equipment

The invention relates to the technical field of signal detection, in particular to mobile phone signal detection equipment, which comprises a central control module; the radio frequency channel simulator is connected with the central control module and is used for receiving the synchronous control instruction and the time-varying channel parameters from the central control module; the space environment simulation device is used for radiofrequency signals and dynamically adjusting space radiation characteristics and link loss of the space environment simulation device based on instructions of the central control module; the protocol stack simulation and signaling interaction module is used for simulating cellular network protocol stack behaviors according to the instruction of the central control module and carrying out signaling interaction with the mobile phone to be tested; a multi-dimensional data acquisition and analysis module; according to the device, the radio frequency channel simulator, the space environment simulation device and the protocol stack simulation module are dispatched in a unified mode through the central control module, complex wireless scenes from geographical environment and channel characteristics to network behaviors can be accurately reproduced, and the reliability and repeatability of testing are greatly improved.
Owner:HUARUI SAIWEI (SUZHOU) TECH CO LTD

Method for verifying data center network performance

PendingUS20260032078A1TransmissionPathPingStation
Packets in a data communications network are encapsulated by an encapsulation module on a sending computer and decapsulated on the receiver computer, the transmission of data packets being controlled by credit sent by the receiving computer to avoid causing congestion. The encapsulation module varies fields in the packets that are used by switches to determine the path to the destination, so as to distribute the load of a transfer across a plurality of paths to the receiving computer. The sending and receiving computers use per path packet delivery, loss, latency and packet trimming information to detect abnormal network behavior and submit alerts and summary statistics to a monitoring station. The monitoring station uses this information to detect network bottlenecks and other faults and to localize them to specific switches or links.
Owner:AVAGO TECHNOLOGIES INTERNATIONAL SALES PTE LTD

False threat intelligence detection method and system based on dynamic graph comparative learning

The invention provides a false threat intelligence detection method and system based on dynamic graph comparative learning. Belongs to the technical field of network security. The method comprises the following steps: acquiring a CTI report to construct a CTI heterogeneous subgraph with semantic features; acquiring a communication network log to construct a real-time network behavior graph; fusing the two into a global heterogeneous time sequence diagram based on an IoC anchor point; respectively constructing feature codes of the CTI semantic view and the network behavior view by utilizing the GAT and the time sequence GNN; minimizing comparison loss through a graph contrast learning (GCL) framework, and learning a unified embedding space; and finally, the embedding distance of the CTI to be verified under the double views is calculated to serve as an abnormal score for detection. Through a semantic-behavior cross validation mechanism, the problems that in the prior art, external reputation is relied on, semantic forgery cannot be recognized and local fact validation is lacked are solved, the accuracy and robustness of threat intelligence detection are remarkably improved, and the method is particularly suitable for scenes such as communication operators with high requirements for data privacy.
Owner:CHINA ACADEMY OF INFORMATION & COMM

Method and system for improving authentication accuracy of MAC address dynamic change scene

The invention relates to the technical field of network communication security, in particular to an authentication accuracy improving method and system for an MAC address dynamic change scene, and the method comprises the steps: building and maintaining a mapping database of a terminal identifier and a historical MAC address sequence, collecting a current MAC in real time, querying the database, extracting the historical MAC sequence during matching, and calculating an associated feature index; and constructing a dynamic authentication feature vector by combining equipment attributes and network behavior features, generating a terminal comprehensive identity confidence coefficient through weighted fusion, and deciding to access according to a preset strategy. According to the method, historical MAC sequence association and multi-feature fusion are utilized, and the authentication accuracy in a dynamic scene is improved. According to the invention, the accuracy and continuity of terminal identity discrimination can be improved in a network environment in which MAC addresses frequently change.
Owner:SOUTH CENTRAL UNIVERSITY FOR NATIONALITIES

A deep learning-based network traffic behavior identification method and system

The application provides a network traffic behavior identification method and system based on deep learning, which determines a plurality of network behavior granularities corresponding to the network traffic data; performs dynamic feature extraction on the network traffic data based on different network behavior granularities to obtain traffic feature vectors corresponding to the different network behavior granularities respectively; obtains each dynamic feature dimension in the traffic feature vector, uses a deep learning model to extract dynamic feature consistency corresponding to each dynamic feature dimension under the condition of multiple behavior granularities respectively, and maps the dynamic feature consistency into corresponding effective behavior monitoring weights; performs behavior security analysis on the network traffic data based on the effective behavior monitoring weights corresponding to each dynamic feature dimension respectively, and sends a security identification result to a network security center; and the application reduces the effective weights of redundant traffic features by identifying the feature consistency of the traffic feature dimensions under different behavior granularities, thereby improving the robustness of network security identification.
Owner:SHANGHAI FUHUA NETWORK TECH CO LTD

Network slice leakage detection and mitigation

Methods, devices, and systems related to detection and mitigation of network slice leakage (when assigned network slices do not function as intended) are disclosed. In one example aspect, a method for wireless communication includes receiving, by a network node, input data related to usage of a network slice configured for a service scenario. The method includes processing, by the network node, the input data based on a set of data features and determining, by the network node, whether the usage of the network slice corresponds to a baseline associated with the network slice, where the baseline is associated with a category that models network behavior for the service scenario.
Owner:T MOBILE US INC

User property safety risk early warning method, device, medium and product

ActiveCN121786758Bretain certain judgmentsAvoid misjudgment of single dataBiological modelsKnowledge representationAttackDiscriminant model
Embodiments of the present application provide a user property safety risk early warning method, device, medium and product, relating to the technical field of communication. The method comprises: based on the user's operator network behavior data, obtaining the user's communication behavior data, location data and application usage data; generating target features according to the communication behavior data, the location data and the application usage data, and constructing an abnormal feature matrix according to the target features; according to the abnormal feature matrix, using a preset statistical generation model, a deep learning discriminant model and a knowledge-driven rule system, respectively generating a first generation result, a second generation result and a third generation result containing the user's risk state, and determining the user's predicted state result based on the three results, and performing corresponding property safety warning behavior based on the predicted state result. The scheme of the present application solves the problem of limitations in the security attack risk of the old people's telecommunication mode.
Owner:CHINA MOBILE GROUP JILIN BRANCH +1

Network security monitoring system based on big data analysis

The application relates to the technical field of computer security, in particular to a network security monitoring system based on big data analysis, which comprises a historical behavior analysis module, a risk assessment module, an attack path analysis module and an emergency response module. According to the application, abnormal fluctuations of network behavior can be accurately identified by real-time monitoring and comparison with historical data, and the specific risk of the abnormal fluctuations to network security can be rapidly evaluated, the accuracy of threat detection is improved, the occurrence of false positives is effectively reduced, abnormal data flow directions can be effectively tracked by analyzing network topology and behavior data, potential attack sources and attack paths can be identified, the timeliness of risk early warning is improved, the identification ability of complex attack modes is enhanced, potential attack links can be rapidly cut off without affecting normal business operations by implementing isolation and service shutdown measures, and the security protection efficiency of the computer network and the stability of the system are optimized.
Owner:STATE GRID SHANDONG ELECTRIC POWER COMPANY WEIFANG POWER SUPPLY

Software upgrading method and system, electronic device and storage medium

Embodiments of the present disclosure provide a software upgrading method, system, electronic device and storage medium. The software upgrading method comprises: adopting a first prediction model to predict an abnormal probability of a cell associated with a first terminal based on first space-time information of the first terminal, wherein the first prediction model is obtained by training a network behavior data collected by a second terminal on a server; and performing a corresponding avoidance operation on an abnormal cell with an abnormal probability greater than a probability threshold.
Owner:ZHIYUAN STAR (SHANGHAI) INTELLIGENT TECHNOLOGY CO LTD