Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

132 results about "Network defense" patented technology

Dynamic honey point collaborative intelligent threat trapping system and method based on genetic algorithm

The invention discloses a dynamic honey point collaborative intelligent threat trapping system and method based on a genetic algorithm in the technical field of network security, and the system comprises a multi-source information collection and dual-mode output module, a reinforcement learning strategy engine, a graph neural network prediction module, a digital twin simulation environment, a strategy verification and optimization module, and a real network defense execution module. A dynamic honey point deployment strategy is generated in real time through a reinforcement learning strategy engine, and the problem of strategy stiffness is solved; a third-generation non-dominated sorting genetic algorithm (NSGA-III) multi-objective optimization algorithm is used for coordinating honey point density adjustment, trip line sensitivity calibration and other actions; attacking path risks are quantified based on a threat scoring formula, digital twin environment pre-verification and high-risk node precise protection are driven, closed-loop linkage of threat perception, strategy optimization and active trapping is finally achieved, and the intelligent defense capability capable of achieving autonomous evolution is formed.
Owner:积至(海南)信息技术有限公司

Network defense agent system based on large language model

The invention belongs to the field of network security, and particularly discloses a network defense agent system based on a large language model. Through the design of the sensing layer, the decision analysis layer and the action execution layer, comprehensive protection of network threats is realized. The sensing layer is responsible for collecting original information from multiple channels and converting the original information into standardized data; the decision analysis layer performs modeling and threat reasoning on attack behaviors, evaluates a risk level and predicts subsequent actions; and the action execution layer specifically executes defense operation according to the defense strategy scheme output by the decision analysis layer. In addition, the application also constructs a data set oriented to attack and defense confrontation, records a complete attack sequence, defense response and effect evaluation thereof, and provides a reliable basis for continuous learning of defense agents. Experimental results show that the framework provided by the invention is superior to the traditional method in the aspects of attack detection accuracy, attack chain identification and defense strategy generation, and has stronger adaptability and real-time response capability.
Owner:HUAZHONG NORMAL UNIV +1

Network defense capability verification method and system based on intrusion attack simulation

The invention provides a network defense capability verification method and system based on intrusion attack simulation. According to the method, network dynamics and a photoacoustic effect simulation technology are creatively fused, and network abnormal traffic equivalent to real attacks is dynamically excited by constructing a photoacoustic coupling waveform driven by network topology; reversely analyzing the vulnerability characteristics based on the protocol interaction entropy, and generating an attack instruction with a space-time cooperation characteristic; utilizing a phase matching algorithm to precisely couple the attack behavior and the network dynamic disturbance to form a defense response track capable of being quantitatively analyzed; and finally, through an asymmetric correlation model, analyzing a dynamic relationship between trajectory deformation and a node survival state, and realizing objective quantitative evaluation of defense efficiency. According to the technical scheme provided by the embodiment of the invention, high-precision quantitative verification of the virtual-real combined network security defense capability can be realized, and the real-time performance and credibility of defense strategy evaluation are improved.
Owner:BEIJING DISTRICT HEATING GRP CO LTD

Self-adaptive game-driven network defense method and system

The invention discloses an adaptive game-driven network defense method and system, and relates to the technical field of network security. The method comprises the following steps: generating a multi-modal bait according to network context information, and screening an optimal bait through credibility evaluation; constructing a time sequence feature tensor according to the network event sequence information of the bait, and obtaining predicted attack information by adopting a pre-trained attack prediction model; combining the network event sequence information of the bait and the predicted attack information to construct a defense income matrix, and carrying out iterative equilibrium solution to obtain an optimal strategy candidate pool; and taking the defense hybrid strategy of the optimal strategy candidate pool as an initial population, performing multi-objective optimization through a non-dominated sorting genetic algorithm to obtain a Pareto optimal strategy set, and performing screening to obtain an execution strategy set for dynamic defense decision making. According to the invention, the dynamic property, intelligence and self-adaptability of network defense are realized, and the ability of a network system to cope with complex attacks is effectively improved.
Owner:XIDIAN UNIV +1

Industrial control and infrastructure defense cooperation method and system based on digital twinning

The invention provides an industrial control and infrastructure defense cooperation method and system based on digital twinning, and relates to the technical field of defense cooperation. The method comprises the following steps: based on a digital twinning technology, collecting sensor data in an industrial control system, and identifying abnormal fluctuation of equipment operation to obtain abnormal activity information; the occurrence frequency and intensity of the deviation data are analyzed, and the network data transmission security of the industrial entity is optimized to obtain security protocol optimization configuration; reconfiguring the network access authority, and monitoring the new access mode and the data flow in real time to obtain an access control optimization state; monitoring network behaviors by using an isolated forest algorithm, and quantitatively evaluating potential internal and external threats to obtain a threat evaluation update log; and adjusting the data acquisition frequency and the processing process based on the update log, and obtaining a dynamic cooperative defense mechanism by updating network defense and response rules. According to the invention, the early warning and response capability of the industrial control system can be optimized.
Owner:JINQICHUANG (BEIJING) TECH CO LTD

Network attack active defense strategy optimization method based on deep reinforcement learning

The invention discloses a network attack active defense strategy optimization method based on deep reinforcement learning, and the method comprises the following steps: collecting multi-source data of a network environment, and carrying out the feature clipping and white list feature reservation; performing normalization and coding processing to generate a security situation vector; constructing a multi-index reward function, and generating an instant reward value and an event-level reward value; executing a double-closed-loop mechanism through an improved PPO model, and respectively outputting an instant strategy instruction and a long-term strategy parameter; performing multi-source evidence commissioning on the instant strategy instruction and the security situation vector, and judging a key evidence loss condition to obtain an execution token; inputting a risk budget pool to carry out resource quota checking, and executing anti-jitter and cooling control; and optimizing parameters of the multi-index reward function through a causal account book. According to the method, rapid response and continuous optimization of various attack behaviors can be realized, the defense effect and the resource utilization rate are considered, the false report and missing report rate is reduced, and the self-adaptability and stability of a network defense system are improved.
Owner:QIAN XINGCHENG NETWORK SECURITY TECH (HUNAN) CO LTD

Power network defense strategy determination method and device, computer equipment and medium

The invention relates to a power network defense strategy determination method and device, computer equipment and a medium. The method comprises the following steps: acquiring operation data of a power network in different time periods; for the operation data in each time period, based on a feature detection model, extracting target operation features in the operation data; determining the operation state of the power network according to the target operation characteristics in different time periods; acquiring attack entity information and defense entity information of the power network aiming at the power network of which the operation state is an abnormal state; the attack entity information is the information of an entity which destroys the power network security; the defense entity information is the information of an entity for protecting the security of the power network; and determining a target defense strategy of the power network according to the attack entity information and the defense entity information. By adopting the method, manual intervention and subjective deviation can be reduced, the method is suitable for a complex and changeable operating environment in a power network, and the comprehensiveness and accuracy of overall detection are improved.
Owner:ELECTRIC POWER RES INST CHINA SOUTHERN POWER GRID CO LTD

Network attack path automatic generation and defense strategy optimization method, system and device and medium

The invention discloses a network attack path automatic generation and defense strategy optimization method, system and device and a medium, and relates to the technical field of network security, and the method comprises the steps: constructing a topology mapping model, obtaining a network architecture, an asset list and a dependency relationship, constructing a visual topology chart, building a vulnerability association analysis model, and combining a vulnerability scanning result. The method comprises the steps of obtaining a vulnerability knowledge graph, optimizing a path calculation process based on the vulnerability knowledge graph, establishing a path derivation model, generating an attack chain by applying a path derivation algorithm, optimizing defense logic, formulating an optimization step model, and establishing a real-time simulation feedback model based on the generated attack chain. And performing simulation implementation on the defense strategy through a multi-level simulation training scheme, and dynamically optimizing the defense strategy according to feedback data. According to the method, the crossing from passive protection to active prediction and from single-point defense to global optimization is realized, and the accuracy and adaptive capacity of network defense are remarkably improved.
Owner:GUIZHOU POWER GRID CO LTD

Power transmission system key plant station identification method considering network-physical cross-domain attack

The invention relates to the technical field of power systems, in particular to a power transmission system key station identification method considering network-physical cross-domain attacks, which comprises the following steps: S1, acquiring defense measure information of a target substation: acquiring a network defense measure configuration condition; s2, constructing a network attack path: proposing the network attack path according to the actual defense condition of the transformer substation; s3, quantitative analysis of attack cost: quantifying the attack cost paid by an attacker in the attack path; s4, attack cost clustering: clustering the attack cost; s5, establishing an attack optimization model: establishing a double-layer optimization model; s6, key plant station identification: solving the double-layer optimization model, finding out system fragile plant station nodes, and carrying out power transmission system key plant station identification; according to the method, the power transmission system can be helped to identify high-risk plant stations in advance, defense resource configuration is optimized, and the cross-domain attack resisting capacity of the power grid is improved.
Owner:NORTH CHINA ELECTRIC POWER UNIV

LLM-based 6G network automatic security processing method and system

The embodiment of the invention provides an LLM-based 6G network automatic security processing method and system. The method is applied to the field of network security intelligent protection, and comprises the following steps: acquiring a network data stream, generating a structured log, extracting features, inputting the features into an intrusion detection model to identify attack behaviors, performing format conversion on a result to generate an LLM model, inputting the LLM model, and reasoning to obtain a network security disposal strategy. And extracting key fields, performing structured packaging, uploading the key fields to a block chain to complete evidence storage and integrity verification, and finally executing corresponding security control operation according to a strategy. According to the scheme, intelligent identification and automatic processing of network attacks are realized, after key fields are extracted, the structured strategy data are generated and uploaded to the block chain system for evidence storage and verification, traceability and data integrity of the processing process are ensured, network defense control which is automatic, high in security and timely in response can be realized, and the network attack processing efficiency is improved. And the intelligent and credible level of network security management is obviously improved.
Owner:TERMINUSBEIJING TECH CO LTD

Active network defense method and system based on watermark and moving target fusion

The invention relates to an active network defense method and system based on watermark and moving target fusion, and the method comprises the steps: obtaining the input and output data of a communication system, and constructing a system model and a holosymmetric polytope observer model according to the input and output data; constructing an attack detector based on the system model and a holosymmetric polytope observer model; and based on the attack detector, the system model and the holosymmetric polytope observer model, watermarking input and output data through a pseudo-random number generation method and a preset target defense function. Through the watermark and moving target removal technology, the problem that the system performance is influenced by an existing watermark method is solved; and meanwhile, false data attacks, denial of service attacks, replay attacks and the like can be detected. In addition, the method is suitable for application scenes needing active attack detection, such as an intelligent connected vehicle system and an intelligent power grid system, and has very high application value.
Owner:WUHAN INST OF TECH

Power-traffic network defense resource configuration method and system considering information security

The invention discloses a power-traffic network defense resource configuration method and system considering information security, and the method comprises the steps: taking the node voltage deviation of a power distribution network as an optimization target as a target function, and taking the defense resource budget as a constraint to construct an upper defender optimization model; constructing a middle-layer false information injection attack model according to the predicted values of the traffic flow and the charge-discharge load of the electric vehicle charging station; constructing a lower-layer dispatching center model according to the network parameters of the power distribution network and the parameters of the infrastructure; converting the middle-layer optimization model and the lower-layer optimization model into an inner-layer single-layer optimization model through a KKT condition, and converting the three-layer optimization model into a double-layer optimization model; and solving the obtained double-layer optimization model to obtain an optimal defense resource configuration strategy. The method provided by the invention provides powerful support for information security defense of the power-traffic coupling network.
Owner:SOUTHEAST UNIV

Network security situation awareness method and system based on deep learning

The invention discloses a network security situation awareness method and system based on deep learning, and the method comprises the steps: generating a time-space sequence data set through integrating a multi-source flow log and a behavior record, extracting the abnormal signal intensity, and generating an embedded vector set representing attack multidimensional through employing a graph representation learning method; and when the abnormal signal intensity exceeds a threshold value, mining time sequence relevance through a sequence analysis model, judging a hidden threat evolution path, updating complex attack chain representation in real time by utilizing a dynamic tracking mechanism, generating future threat probability distribution by fusing a risk prediction method, and determining a high-risk threat priority sequence. For high-risk threats, an early warning mechanism is activated through infrastructure influence assessment, a safety guarantee protocol is integrated, a protection layer is applied, and enhanced network defense configuration is generated. According to the embodiment, through integration of spatio-temporal data fusion, dynamic threat tracking and risk prediction, the detection precision and response speed of hidden threats are remarkably improved, and the safety of key infrastructures is guaranteed.
Owner:HUNAN JIEYIXIN TECH CO LTD

Network asset risk identification method and system

The invention discloses a network asset risk identification method and system, and the method comprises the steps: obtaining a network data flow, generating a list containing exposed assets, carrying out the feature analysis in combination with the historical data of the exposed assets, screening out candidate assets meeting an abnormal communication mode, carrying out the correlation analysis of the flow change data of any two candidate assets, and carrying out the risk identification of the network assets. Therefore, an asset interaction map is constructed, candidate attack paths are determined, then a target attack path is screened out through service analysis, and finally network assets with risks are identified from the target path. According to the method, dynamic perception and accurate risk positioning of known and unknown assets are realized, sudden attack initiated by APT attack by utilizing asset state fluctuation is effectively captured, the ability of resisting APT depth penetration is improved, and the timeliness and effectiveness of network defense are enhanced.
Owner:STATE GRID ZHEJIANG ELECTRIC POWER CO LTD HANGZHOU POWER SUPPLY CO

Power network distributed cooperative defense method, system and device based on graph neural network, and storage medium

The invention relates to the technical field of power network security protection, in particular to a power network distributed cooperative defense method, system and device based on a graph neural network and a storage medium. The method comprises the following steps of: constructing a multi-relation graph structure comprising a master station, a substation and terminal equipment, and extracting node local embedding and full-graph-level situation embedding by adopting a graph neural network; establishing a centralized evaluation network to carry out topological position differentiation evaluation, and constructing a distributed action execution network to realize localized defense decision; a centralized training and distributed execution mechanism is adopted, a global strategy is uniformly optimized in a training stage, and each node independently executes a defense action in an execution stage; strategy iteration optimization is carried out through defense execution feedback, and attack mode changes are dynamically adapted. The technical problems of insufficient topology utilization, high response time delay and weak adaptive capacity in traditional power network defense are solved.
Owner:GUIZHOU POWER GRID CO LTD

Network defense system vulnerability simulation method based on generative adversarial network

The invention discloses a network defense system vulnerability simulation method based on a generative adversarial network. The method comprises the following steps: S1, generating a network security situation awareness data set; s2, obtaining a weighted attack path graph; s3, performing graph semantic coding on the weighted attack path graph, and mapping a condition vector set; s4, obtaining a converged candidate weak point configuration set; s5, generating a target weak point configuration list; s6, forming a weak bait cluster; and S7, collecting a detection behavior log aiming at the weak bait cluster in real time, generating an attacker interaction behavior data set by utilizing the behavior log and the transverse movement behavior log, updating a weighted attack path graph and a condition vector set based on the attacker interaction behavior data set, and performing online fine adjustment on the condition generative adversarial network to obtain a weighted attack path graph. And the step S5 and the step S6 are executed again. According to the invention, through comprehensive discrimination and constraint optimization, unification of high trapping value and low business risk is realized.
Owner:BEIJING RUISJINDA TECH CO LTD

Network security defense decision-making method

The invention discloses a network security defense decision-making method, and particularly relates to the technical field of network security. The method comprises the following steps: acquiring user account access behavior data in a network environment and intrusion observation data output by an intrusion detector, and performing data cleaning and feature extraction to obtain historical trust evidence sequence data; performing time sequence feature analysis by using a recurrent neural network, and identifying an abnormal behavior mode of the account; trust evaluation is carried out based on an actor-commentator reinforcement learning algorithm, and account real-time trust score data is generated; performing association analysis by combining the behavior abnormal mode feature data and the real-time trust score data to obtain potential threat feature data of the user account; evaluating the effectiveness of the defense strategy by adopting a strategy evaluation network, and generating defense strategy evaluation data; and generating an optimal network defense decision according to the potential threat feature data of the user account and the defense strategy evaluation data. According to the method, the detection accuracy of potential network intrusion and the effectiveness of defense measures are improved.
Owner:UNIV OF SCI & TECH BEIJING

Automatic defense system for computer network security

The invention discloses an automatic defense system for computer network security, and the system comprises a quantum random walk edge real-time detection module which is responsible for capturing a data flow in a network in real time, and detecting the abnormal transition in the data flow through a quantum random walk model; the hyper-chaos time sequence prediction module is used for performing time sequence prediction on the data flow by utilizing a hyper-chaos neural network, identifying potential security threats, quantifying the chaos degree of the system through a Lyapunov index, dynamically setting an abnormal threshold value, and sending out an early warning signal when a prediction result exceeds the threshold value; the quantum key distribution cross-system collaboration module is used for encrypting threat intelligence exchange between external systems by using a quantum key distribution technology, and meanwhile, through an intelligent contract automation mechanism, when specific conditions are met, a whole-network defense action is automatically triggered; and the dynamic causal reasoning real-time feedback module is used for constructing a processor-network-application causal Bayesian network, and quickly positioning and blocking a threat source by deducing an attack propagation path in real time.
Owner:GUANGXI UNIV OF CHINESE MEDICINE

Advanced network threat intelligent detection and defense system

The invention discloses an advanced network threat intelligent detection and defense system and method in the technical field of network defense. The system comprises a data acquisition module which analyzes encrypted traffic through a deep packet inspection technology and marks space-time metadata; the feature extraction module is used for constructing a node behavior association graph by adopting a multi-scale sliding window and a graph neural network; the detection engine module integrates multi-model parallel analysis of LSTM, random forest and the like, and dynamically fuses detection results through an entropy weight method; and the defense execution module is used for realizing flow cleaning and virtual trapping node deployment based on an SDN (Software Defined Network) technology. The method comprises the steps of protocol extension field reverse analysis, covert channel time sequence correlation analysis and dynamic network topology adjustment. According to the method, the encryption APT attack detection accuracy reaches 98.7%, the false alarm rate is reduced to 0.15%, the defense strategy effective time is shorter than 1 second, and the method is suitable for complex network environments such as cloud computing and industrial Internet of Things.
Owner:GUOANYUN (XIAN) TECH GRP CO LTD

Network defense method and device, equipment, storage medium and computer program product

The invention relates to the technical field of network security, and discloses a network defense method, device and equipment, a storage medium and a computer program product.The method comprises the steps that whether malicious oscillation exists or not is judged according to at least one of route change information of a border gateway protocol, a time window threshold value and a route updating frequency threshold value; and analyzing the current traffic characteristics through an attack detection model, judging whether an attack behavior of distributed denial of service exists, limiting the speed of the current network traffic according to the malicious oscillation characteristics, and guiding the attack traffic of the attack behavior to a black hole address based on the extracted attack characteristics. According to the application, malicious oscillation and attack behaviors are monitored and identified in real time, when malicious oscillation is detected, the speed of the current network flow is limited according to the characteristics of the malicious oscillation, for the attack behaviors, the attack flow is guided to the black hole address based on the extracted attack characteristics, the attack source is quickly blocked, and a dual detection and response mechanism is adopted. And the timeliness and effectiveness of network defense are improved.
Owner:SHENZHEN FENGRUNDA TECH CO LTD

Firewall dynamic policy adaptation method and system based on big data

The invention discloses a firewall dynamic policy adaptation method and system based on big data, and the method comprises the steps: collecting multi-source heterogeneous data in a network, and constructing a dynamic network entity map in real time; processing the time sequence of the atlas by using a preset time sequence diagram attention network model to obtain a behavior fingerprint vector representing the behavior state of the entity, and calculating the risk score of the entity; when the risk score exceeds a risk threshold value, automatically generating a temporary security policy for managing and controlling the access behavior of the entity; and managing the life cycle of the temporary security policy, and automatically updating, renewing or cancelling according to the entity risk state change. According to the method, the network entity behavior baseline is constructed and the risk prediction is carried out, so that the conversion from passive defense to active defense is realized, the security policy can be automatically and accurately generated and managed, advanced persistent threats and zero-day attacks can be effectively coped with, and the self-adaptability and the intelligent level of network defense are improved.
Owner:HANGZHOU TAICHENG NETWORK TECH CO LTD

Network multi-step attack prediction method based on space-time fusion dynamic graph convolution

The invention relates to a network multi-step attack prediction method based on space-time fusion dynamic graph convolution. Compared with the prior art, the defect that network attack prediction is difficult to meet actual application requirements is overcome. The method comprises the following steps: extracting network alarm attributes; performing data preprocessing on the alarm attribute data; constructing a network multi-step attack prediction model; and performing multi-step attack prediction. According to the method, the attack probability can be predicted, and the specific parameters of the expected attack can be predicted, so that better network defense measures can be applied.
Owner:HEFEI CITY COULD DATA CENT

Method, device and equipment for predicting network security state of border gateway protocol

The invention discloses a network security state prediction method and device of a border gateway protocol, equipment and a readable storage medium, and relates to the technical field of Internet. Comprising the following steps: acquiring relevant parameters of a border gateway protocol; the related parameters comprise the attack prefix injection rate, the network defense capability and the attacked prefix importance of the border gateway protocol; determining the attack risk of the border gateway protocol based on the related parameters of the border gateway protocol; and calculating a network security state prediction result of the border gateway protocol based on the attack risk and the initial transition probability matrix of the border gateway protocol. According to the method, the accuracy of network security state prediction is improved.
Owner:SUZHOU IND PARK SERVICE OUTSOURCING VOCATIONAL COLLEGE (SUZHOU SERVICE OUTSOURCING TALENT TRAINING & TRAINING CENT)

Real-time network intrusion prevention method based on multi-source data fusion

The invention discloses a real-time network intrusion prevention method based on multi-source data fusion, and particularly relates to the technical field of network defense. According to the method, the sampling frequency is determined according to the time granularity difference of different data sources, flexible time windows are divided, the abnormal behaviors in the network are accurately identified by extracting network behavior characteristics such as granularity matching degree and time synchronization degree and combining a machine learning model for analysis, and the abnormal behaviors in the network are accurately identified after the abnormal behaviors are identified. And the system triggers a corresponding alarm mechanism according to the severity of the behavior and takes corresponding defense measures, so that effective detection and response to complex network intrusion are realized, and the network security protection capability is remarkably improved.
Owner:HEFEI TANOVO INFORMATION SECURITY TECH CO LTD

System and method for autonomously fingerprinting and enumerating internet of thing (IoT) devices based on nated IPFIX and DNS traffic

This document describes a system and method for detecting the presence of Internet of Things (IoTs) from network traffic that has undergone a Network Address Translation (NAT) process, i.e., NATed network traffic, regardless of whether the network traffic comprises IP Flow Information Export (IPFIX) type of traffic or Domain Name System (DNS) type of traffic. Such a capability is crucial as the adoption rate of IoTs have increased exponentially over the past few years. In order to protect IoTs from cyber-attacks, one would first have to understand what type of IoTs are being used, and how many / how widely used these IoTs are. Once the IoT landscape has been defined, cyber defenders may then dedicate resources to identify and subsequently address vulnerabilities that may be in these IoTs.
Owner:ENSIGN INFOSECURITY PTE LTD

Network defense method and device

The invention provides a network defense method and device, which can be applied to the technical field of network security. The method comprises: based on a plurality of devices in a power grid system, determining a device topological graph, the device topological graph comprising devices and edges, the edges representing communication relationships among the plurality of devices; inputting the equipment topological graph into a topological encoder to obtain equipment topological characteristics; dividing a plurality of devices in the power grid system based on the device topological features, the device attribute features of the plurality of devices and the edge attribute features of the plurality of edges in the device topological graph to obtain a plurality of security domains and a global domain, the security domains comprising at least one device having an intra-domain communication relationship, and the global domain comprising at least one device having an intra-domain communication relationship; the global domain comprises a plurality of security domains with inter-domain communication relations; and based on the respective state vectors of the plurality of security domains and the state vector of the global domain, respectively obtaining network defense action information of each device. According to the method, efficient utilization of intra-domain resources and the threat protection capability in the domain can be ensured.
Owner:ELECTRIC POWER SCI & RES INST OF STATE GRID TIANJIN ELECTRIC POWER CO +3

Block chain distributed consensus-based satellite network intelligent defense method and system

The invention relates to the technical field of network defense, in particular to a satellite network intelligent defense method and system based on block chain distributed consensus. The method comprises the following steps: collecting satellite network node time sequence flow data, carrying out modeling analysis on the data through a long and short term memory network, predicting a data flow of a next time window, comparing a standard communication mode, identifying abnormal flow data, and generating an abnormal communication behavior identification result. According to the invention, the monitoring and analysis of the data stream are optimized by integrating the long-short-term memory network, the future data stream can be accurately predicted, the deviation from the standard mode can be detected in real time, the accuracy and speed of anomaly detection are effectively enhanced, the connection between nodes and the flow direction of the data packet are analyzed, and the potential intrusion path is accurately identified. The transparency and consistency of data verification are ensured through a block chain technology, the instant updating capability of a defense strategy is enhanced, and the adaptability and response speed of the whole network are improved, so that continuous and stable operation of the communication network is ensured.
Owner:XINGCHEN XUANJI (BEIJING) MEASUREMENT & CONTROL TECHNOLOGY CO LTD

Network threat analysis method and system based on learning evolutionary game

According to the network threat analysis method and system based on the learning evolutionary game provided by the invention, the expected benefit of sharing is analyzed through modeling, quantitative analysis is carried out by adopting the learning evolutionary game, and a reasonable incentive strategy is obtained, so that the sharing and utilization efficiency of network threat intelligence is promoted; each entity enterprise inquires from the open community to obtain the required threat intelligence, analyzes the threat intelligence and deploys own network defense measures, so that the network security defense capability is improved, and the problems that in the prior art, the capability of providing a large number of resources is difficult, the data sharing and exchanging capability is weak, and a large number of continuous network attacks are difficult to defend are solved.
Owner:北京国瑞数智技术有限公司

Network deception resource defense method based on deep learning

The invention discloses a network deception resource defense method based on deep learning, and relates to the technical field of network deception resource defense, and the method comprises the steps: S1, building a network target defense network, and carrying out the camouflage deployment of a network target needing to be protected through a camouflage simulation module; s2, monitoring the camouflage simulation module in real time through a danger sensing module, and performing display early warning operation through a user side interface; s3, when the user needs to use the network resources in the data center, analyzing whether the network resources are deception resources or not through an analysis and identification subsystem; and S4, analyzing the deception resources through a deep learning subsystem, finding out a common point of the deception resources, and performing automatic identification and marking operation on other network resources. According to the invention, the feature information of the network resources is collected in multiple dimensions, the malicious data in the network resources can be accurately identified and marked, and the network defense effect is improved.
Owner:LUOYANG INST OF SCI & TECH

An unmanned aerial vehicle data collection optimization method based on matrix completion and trust evaluation

PendingCN122373092AData packSimulation
This invention proposes an optimized method for drone data acquisition based on matrix completion and trust assessment, applicable to drone forensics in IoT network defense. First, in matrix completion, the sampling point locations and data packet acquisition times are constructed into a matrix, and matrix completion technology is used to recover all information and select sampling points. Second, in the drone flight trajectory, the selected sampling points and the Elite Ant Trail Optimization (EATO) algorithm are combined to optimize the drone's flight trajectory. Third, in the trust evolution mechanism, the comprehensive trust level of sensor nodes is obtained through dual evaluation by neighboring nodes and the drone. The proposed method can solve the security risks and resource consumption problems of data acquisition from IoT smart devices, effectively identify malicious nodes, optimize the accuracy of trust assessment, improve network security, and reduce drone energy consumption.
Owner:GUANGXI UNIV +1