Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

82 results about "Network defense" patented technology

Network defense agent system based on large language model

The invention belongs to the field of network security, and particularly discloses a network defense agent system based on a large language model. Through the design of the sensing layer, the decision analysis layer and the action execution layer, comprehensive protection of network threats is realized. The sensing layer is responsible for collecting original information from multiple channels and converting the original information into standardized data; the decision analysis layer performs modeling and threat reasoning on attack behaviors, evaluates a risk level and predicts subsequent actions; and the action execution layer specifically executes defense operation according to the defense strategy scheme output by the decision analysis layer. In addition, the application also constructs a data set oriented to attack and defense confrontation, records a complete attack sequence, defense response and effect evaluation thereof, and provides a reliable basis for continuous learning of defense agents. Experimental results show that the framework provided by the invention is superior to the traditional method in the aspects of attack detection accuracy, attack chain identification and defense strategy generation, and has stronger adaptability and real-time response capability.
Owner:HUAZHONG NORMAL UNIV +1

Self-adaptive game-driven network defense method and system

The invention discloses an adaptive game-driven network defense method and system, and relates to the technical field of network security. The method comprises the following steps: generating a multi-modal bait according to network context information, and screening an optimal bait through credibility evaluation; constructing a time sequence feature tensor according to the network event sequence information of the bait, and obtaining predicted attack information by adopting a pre-trained attack prediction model; combining the network event sequence information of the bait and the predicted attack information to construct a defense income matrix, and carrying out iterative equilibrium solution to obtain an optimal strategy candidate pool; and taking the defense hybrid strategy of the optimal strategy candidate pool as an initial population, performing multi-objective optimization through a non-dominated sorting genetic algorithm to obtain a Pareto optimal strategy set, and performing screening to obtain an execution strategy set for dynamic defense decision making. According to the invention, the dynamic property, intelligence and self-adaptability of network defense are realized, and the ability of a network system to cope with complex attacks is effectively improved.
Owner:XIDIAN UNIV +1

Network attack active defense strategy optimization method based on deep reinforcement learning

The invention discloses a network attack active defense strategy optimization method based on deep reinforcement learning, and the method comprises the following steps: collecting multi-source data of a network environment, and carrying out the feature clipping and white list feature reservation; performing normalization and coding processing to generate a security situation vector; constructing a multi-index reward function, and generating an instant reward value and an event-level reward value; executing a double-closed-loop mechanism through an improved PPO model, and respectively outputting an instant strategy instruction and a long-term strategy parameter; performing multi-source evidence commissioning on the instant strategy instruction and the security situation vector, and judging a key evidence loss condition to obtain an execution token; inputting a risk budget pool to carry out resource quota checking, and executing anti-jitter and cooling control; and optimizing parameters of the multi-index reward function through a causal account book. According to the method, rapid response and continuous optimization of various attack behaviors can be realized, the defense effect and the resource utilization rate are considered, the false report and missing report rate is reduced, and the self-adaptability and stability of a network defense system are improved.
Owner:QIAN XINGCHENG NETWORK SECURITY TECH (HUNAN) CO LTD

Network attack path automatic generation and defense strategy optimization method, system and device and medium

The invention discloses a network attack path automatic generation and defense strategy optimization method, system and device and a medium, and relates to the technical field of network security, and the method comprises the steps: constructing a topology mapping model, obtaining a network architecture, an asset list and a dependency relationship, constructing a visual topology chart, building a vulnerability association analysis model, and combining a vulnerability scanning result. The method comprises the steps of obtaining a vulnerability knowledge graph, optimizing a path calculation process based on the vulnerability knowledge graph, establishing a path derivation model, generating an attack chain by applying a path derivation algorithm, optimizing defense logic, formulating an optimization step model, and establishing a real-time simulation feedback model based on the generated attack chain. And performing simulation implementation on the defense strategy through a multi-level simulation training scheme, and dynamically optimizing the defense strategy according to feedback data. According to the method, the crossing from passive protection to active prediction and from single-point defense to global optimization is realized, and the accuracy and adaptive capacity of network defense are remarkably improved.
Owner:GUIZHOU POWER GRID CO LTD

LLM-based 6G network automatic security processing method and system

The embodiment of the invention provides an LLM-based 6G network automatic security processing method and system. The method is applied to the field of network security intelligent protection, and comprises the following steps: acquiring a network data stream, generating a structured log, extracting features, inputting the features into an intrusion detection model to identify attack behaviors, performing format conversion on a result to generate an LLM model, inputting the LLM model, and reasoning to obtain a network security disposal strategy. And extracting key fields, performing structured packaging, uploading the key fields to a block chain to complete evidence storage and integrity verification, and finally executing corresponding security control operation according to a strategy. According to the scheme, intelligent identification and automatic processing of network attacks are realized, after key fields are extracted, the structured strategy data are generated and uploaded to the block chain system for evidence storage and verification, traceability and data integrity of the processing process are ensured, network defense control which is automatic, high in security and timely in response can be realized, and the network attack processing efficiency is improved. And the intelligent and credible level of network security management is obviously improved.
Owner:TERMINUSBEIJING TECH CO LTD

Network security situation awareness method and system based on deep learning

The invention discloses a network security situation awareness method and system based on deep learning, and the method comprises the steps: generating a time-space sequence data set through integrating a multi-source flow log and a behavior record, extracting the abnormal signal intensity, and generating an embedded vector set representing attack multidimensional through employing a graph representation learning method; and when the abnormal signal intensity exceeds a threshold value, mining time sequence relevance through a sequence analysis model, judging a hidden threat evolution path, updating complex attack chain representation in real time by utilizing a dynamic tracking mechanism, generating future threat probability distribution by fusing a risk prediction method, and determining a high-risk threat priority sequence. For high-risk threats, an early warning mechanism is activated through infrastructure influence assessment, a safety guarantee protocol is integrated, a protection layer is applied, and enhanced network defense configuration is generated. According to the embodiment, through integration of spatio-temporal data fusion, dynamic threat tracking and risk prediction, the detection precision and response speed of hidden threats are remarkably improved, and the safety of key infrastructures is guaranteed.
Owner:HUNAN JIEYIXIN TECH CO LTD

Network asset risk identification method and system

The invention discloses a network asset risk identification method and system, and the method comprises the steps: obtaining a network data flow, generating a list containing exposed assets, carrying out the feature analysis in combination with the historical data of the exposed assets, screening out candidate assets meeting an abnormal communication mode, carrying out the correlation analysis of the flow change data of any two candidate assets, and carrying out the risk identification of the network assets. Therefore, an asset interaction map is constructed, candidate attack paths are determined, then a target attack path is screened out through service analysis, and finally network assets with risks are identified from the target path. According to the method, dynamic perception and accurate risk positioning of known and unknown assets are realized, sudden attack initiated by APT attack by utilizing asset state fluctuation is effectively captured, the ability of resisting APT depth penetration is improved, and the timeliness and effectiveness of network defense are enhanced.
Owner:STATE GRID ZHEJIANG ELECTRIC POWER CO LTD HANGZHOU POWER SUPPLY CO

Power network distributed cooperative defense method, system and device based on graph neural network, and storage medium

The invention relates to the technical field of power network security protection, in particular to a power network distributed cooperative defense method, system and device based on a graph neural network and a storage medium. The method comprises the following steps of: constructing a multi-relation graph structure comprising a master station, a substation and terminal equipment, and extracting node local embedding and full-graph-level situation embedding by adopting a graph neural network; establishing a centralized evaluation network to carry out topological position differentiation evaluation, and constructing a distributed action execution network to realize localized defense decision; a centralized training and distributed execution mechanism is adopted, a global strategy is uniformly optimized in a training stage, and each node independently executes a defense action in an execution stage; strategy iteration optimization is carried out through defense execution feedback, and attack mode changes are dynamically adapted. The technical problems of insufficient topology utilization, high response time delay and weak adaptive capacity in traditional power network defense are solved.
Owner:GUIZHOU POWER GRID CO LTD

Network defense system vulnerability simulation method based on generative adversarial network

The invention discloses a network defense system vulnerability simulation method based on a generative adversarial network. The method comprises the following steps: S1, generating a network security situation awareness data set; s2, obtaining a weighted attack path graph; s3, performing graph semantic coding on the weighted attack path graph, and mapping a condition vector set; s4, obtaining a converged candidate weak point configuration set; s5, generating a target weak point configuration list; s6, forming a weak bait cluster; and S7, collecting a detection behavior log aiming at the weak bait cluster in real time, generating an attacker interaction behavior data set by utilizing the behavior log and the transverse movement behavior log, updating a weighted attack path graph and a condition vector set based on the attacker interaction behavior data set, and performing online fine adjustment on the condition generative adversarial network to obtain a weighted attack path graph. And the step S5 and the step S6 are executed again. According to the invention, through comprehensive discrimination and constraint optimization, unification of high trapping value and low business risk is realized.
Owner:BEIJING RUISJINDA TECH CO LTD

Network security defense decision-making method

The invention discloses a network security defense decision-making method, and particularly relates to the technical field of network security. The method comprises the following steps: acquiring user account access behavior data in a network environment and intrusion observation data output by an intrusion detector, and performing data cleaning and feature extraction to obtain historical trust evidence sequence data; performing time sequence feature analysis by using a recurrent neural network, and identifying an abnormal behavior mode of the account; trust evaluation is carried out based on an actor-commentator reinforcement learning algorithm, and account real-time trust score data is generated; performing association analysis by combining the behavior abnormal mode feature data and the real-time trust score data to obtain potential threat feature data of the user account; evaluating the effectiveness of the defense strategy by adopting a strategy evaluation network, and generating defense strategy evaluation data; and generating an optimal network defense decision according to the potential threat feature data of the user account and the defense strategy evaluation data. According to the method, the detection accuracy of potential network intrusion and the effectiveness of defense measures are improved.
Owner:UNIV OF SCI & TECH BEIJING

Firewall dynamic policy adaptation method and system based on big data

The invention discloses a firewall dynamic policy adaptation method and system based on big data, and the method comprises the steps: collecting multi-source heterogeneous data in a network, and constructing a dynamic network entity map in real time; processing the time sequence of the atlas by using a preset time sequence diagram attention network model to obtain a behavior fingerprint vector representing the behavior state of the entity, and calculating the risk score of the entity; when the risk score exceeds a risk threshold value, automatically generating a temporary security policy for managing and controlling the access behavior of the entity; and managing the life cycle of the temporary security policy, and automatically updating, renewing or cancelling according to the entity risk state change. According to the method, the network entity behavior baseline is constructed and the risk prediction is carried out, so that the conversion from passive defense to active defense is realized, the security policy can be automatically and accurately generated and managed, advanced persistent threats and zero-day attacks can be effectively coped with, and the self-adaptability and the intelligent level of network defense are improved.
Owner:HANGZHOU TAICHENG NETWORK TECH CO LTD

System and method for autonomously fingerprinting and enumerating internet of thing (IoT) devices based on nated IPFIX and DNS traffic

This document describes a system and method for detecting the presence of Internet of Things (IoTs) from network traffic that has undergone a Network Address Translation (NAT) process, i.e., NATed network traffic, regardless of whether the network traffic comprises IP Flow Information Export (IPFIX) type of traffic or Domain Name System (DNS) type of traffic. Such a capability is crucial as the adoption rate of IoTs have increased exponentially over the past few years. In order to protect IoTs from cyber-attacks, one would first have to understand what type of IoTs are being used, and how many / how widely used these IoTs are. Once the IoT landscape has been defined, cyber defenders may then dedicate resources to identify and subsequently address vulnerabilities that may be in these IoTs.
Owner:ENSIGN INFOSECURITY PTE LTD

Network threat analysis method and system based on learning evolutionary game

PendingCN121485949AUser identity/authority verificationCyber threat intelligenceEngineering
According to the network threat analysis method and system based on the learning evolutionary game provided by the invention, the expected benefit of sharing is analyzed through modeling, quantitative analysis is carried out by adopting the learning evolutionary game, and a reasonable incentive strategy is obtained, so that the sharing and utilization efficiency of network threat intelligence is promoted; each entity enterprise inquires from the open community to obtain the required threat intelligence, analyzes the threat intelligence and deploys own network defense measures, so that the network security defense capability is improved, and the problems that in the prior art, the capability of providing a large number of resources is difficult, the data sharing and exchanging capability is weak, and a large number of continuous network attacks are difficult to defend are solved.
Owner:北京国瑞数智技术有限公司

An unmanned aerial vehicle data collection optimization method based on matrix completion and trust evaluation

PendingCN122373092AData packSimulation
This invention proposes an optimized method for drone data acquisition based on matrix completion and trust assessment, applicable to drone forensics in IoT network defense. First, in matrix completion, the sampling point locations and data packet acquisition times are constructed into a matrix, and matrix completion technology is used to recover all information and select sampling points. Second, in the drone flight trajectory, the selected sampling points and the Elite Ant Trail Optimization (EATO) algorithm are combined to optimize the drone's flight trajectory. Third, in the trust evolution mechanism, the comprehensive trust level of sensor nodes is obtained through dual evaluation by neighboring nodes and the drone. The proposed method can solve the security risks and resource consumption problems of data acquisition from IoT smart devices, effectively identify malicious nodes, optimize the accuracy of trust assessment, improve network security, and reduce drone energy consumption.
Owner:GUANGXI UNIV +1

Communication network defense processing method, storage medium and electronic device

PendingCN122348841AAttackSimulation
The application discloses a defense processing method of a communication network, a storage medium and an electronic device. It relates to the technical field of network security, and the method comprises the following steps: determining a plurality of initial attack resource quantities based on the respective corresponding traffic data of a plurality of device nodes in a target communication network within a preset time window; determining a plurality of initial defense resource quantities based on the plurality of initial attack resource quantities and the respective corresponding node importance degrees of the plurality of device nodes; determining a target function of the target communication network based on the plurality of initial attack resource quantities, the respective corresponding node importance degrees of the plurality of device nodes and the plurality of initial defense resource quantities; and optimizing the plurality of initial defense resource quantities to obtain a plurality of target defense resource quantities, with the maximum function value of the target function as the optimization target. The application solves the technical problem that, due to the fact that the related art does not comprehensively consider factors when facing a complex attack-defense scene, the adaptability of a defense strategy in an actual network environment is insufficient.
Owner:STATE GRID BEIJING ELECTRIC POWER CO +1

Network security product interconnection method and system based on elastic scheduling

PendingCN122660927APathPingCritical information infrastructure
The application discloses a network security product interconnection and intercommunication method and system based on elastic scheduling, and belongs to the technical field of network security. In order to solve the technical problems of poor compatibility, difficulty in dynamically adapting network environment fluctuation and low cooperative defense efficiency caused by manufacturer barriers among network security products, the application obtains standard data by uniformly converting the protocols, interfaces and data formats of each security product; determines target scheduling instructions based on the standard state data and performs elastic adjustment of paths, tasks and resources by using a strategy and a value network; generates global threat intelligence based on standard threat data and distributes cooperative protection strategies; and performs abnormal monitoring and self-repairing on the adjusted running state. The application can be widely applied to the key information infrastructure scene of multi-type security product cooperative protection, and significantly improves the resource utilization rate and the reliability of network defense.
Owner:INSTITUTE OF INFORMATION ENGINEERING CHINESE ACADEMY OF SCIENCES

Methods and systems for efficient adaptive logging of cyber threat incidents

ActiveUS12603862B2Securing communicationData packCyber threat intelligence
A packet-filtering network appliance such as a threat intelligence gateway (TIG) protects TCP / IP networks from Internet threats by enforcing certain policies on in-transit packets that are crossing network boundaries. The policies are composed of packet filtering rules derived from cyber threat intelligence (CTI). Logs of rule-matching packets and their associated flows are sent to cyberanalysis applications located at security operations centers (SOCs) and operated by cyberanalysts. Some cyber threats / attacks, or incidents, are composed of many different flows occurring at a very high rate, which generates a flood of logs that may overwhelm computer, storage, network, and cyberanalysis resources, thereby compromising cyber defenses. The present disclosure describes incident logging, in which a single incident log efficiently incorporates the logs of the many flows that comprise the incident, thereby potentially reducing resource consumption while improving the informational / cyberanalytical value of the incident log for cyberanalysis when compared to the component flow logs. Incident logging vs. flow logging can be automatically and adaptively switched on or off depending on the combination of resource consumption and informational / cyberanalytical value.
Owner:CENTRIPETAL NETWORKS INC

A dynamic security defense method and system based on thermal migration and deep learning

ActiveCN116318779BAttackHoneypot
The application discloses a kind of dynamic security defense method and system based on thermal migration and deep learning, by preliminary discrimination of traffic using intrusion detection system, again using the malicious traffic detection module based on deep learning review and determine as malicious traffic, SDN controller forwards traffic to low interaction honeypot, when attack depth reaches critical point, the copy of normal host of timed snapshot is activated as high interaction honeypot by honeypot management system, then using redirection forwarding engine TCP_REPAIR agent switches connection to high interaction honeypot.The application relates to the field of network defense technology, uses the malicious traffic detection technology based on deep learning, accurately shunts encrypted or non-encrypted normal and malicious traffic, makes up the defect that traditional defense system can only detect non-encrypted traffic, simultaneously using TCP thermal migration technology, optimizes the shortcomings of long time consumption and non-concealed switching in traditional TCP connection switching process, effectively improves the dynamic defense capability of system and utilization rate and decoy capability of honeypot cluster.
Owner:GUILIN UNIV OF ELECTRONIC TECH

Method and device for identifying C2 address, electronic equipment and storage medium

The invention provides a method and device for identifying a C2 address, electronic equipment and a storage medium, and relates to the technical field of security. According to the method, the C2 address is identified by analyzing the Botnet traffic, identifying the traffic of DNS and TCP protocol sessions and counting the traffic characteristics, so that the key characteristics of Botnet communication can be captured in time without depending on a preset rule, and the attack mode of a novel Botnet virus family can be quickly adapted. Compared with a traditional detection method based on IDS, the scheme effectively solves the problem that the defense capability is lagged due to attack changes, the real-time performance and accuracy of detection are greatly improved, network defense can respond to new threats more quickly, and the overall network security protection efficiency is enhanced.
Owner:QI AN XIN TECHNOLOGY GROUP INC

Network defense method and device, equipment, program product and storage medium

The invention discloses a network defense method and device, equipment, a program product and a storage medium, and the method comprises the steps: receiving a first message sent by first equipment, and collecting N flow logs of the first equipment according to the first message, N being a positive integer; performing identity authentication on the first equipment according to the first source IP of the first message; if the identity authentication of the first device is passed, whether M second source IPs corresponding to the N flow logs comprise attacked IPs is judged according to the N flow logs, and M is a positive integer and is smaller than or equal to N; and if the M second source IPs comprise the attacked IP, reducing the flow corresponding to the attacked IP.
Owner:CHINA MOBILE (SUZHOU) SOFTWARE TECH CO LTD +1

Method and system for implementing a service that simplifies network cyber defense capabilities

ActiveUS12665919B2Securing communicationCyber defenseEngineering
A method, system, and computer-readable storage medium for implementing a service that simplifies network cyber defense capabilities. The method includes: compiling a resource list of resources that exist within a computer network; compiling a cyber defense list of cyber defense mechanisms that exist within the computer network; evaluating the resources and the cyber defense mechanisms, against any applicable threats or vulnerabilities, to determine whether there are any threats to the computer network or any vulnerabilities to that network; and generating a visual indication of any of the computer network's threats or vulnerabilities. The resource list may include a resource configuration of the resources, and the cyber defense list may include a cyber defense configuration of the cyber defense mechanisms.
Owner:JPMORGAN CHASE BANK NA

Network defense detection method and device, equipment, storage medium and product thereof

The invention discloses a network defense detection method, device and equipment, a storage medium and a product thereof, and relates to the technical field of network security, the method is applied to a coprocessor module arranged in a terminal, the coprocessor module is used for network security testing, and the method comprises the following steps: monitoring a network service enabling event of the terminal, loading a corresponding attack script according to the started service to carry out a network security test; in the testing process, comparing a first transfer path of the protocol state expected by the attack script with a second transfer path of the protocol state actually executed by the main processor, and judging whether the first transfer path is consistent with the second transfer path or not; and if the first transfer path is not consistent with the second transfer path, determining that an exception exists in the test, and controlling a communication module of the terminal to repair the corresponding security hole. That is, the whole process from vulnerability identification to communication layer repair can be completed without depending on external network interaction, so that the autonomous defense capability of the Internet of Things terminal in a complex network environment is enhanced.
Owner:PANASONIC APPLIANCES (CHINA) CO LTD

Adaptive network defense and topology reconstruction system based on attack feature learning

The invention discloses a self-adaptive network defense and topology reconstruction system based on attack feature learning, and the system comprises a data collection and preprocessing module which is used for collecting network state data and attack information in real time, and carrying out the preprocessing of the collected data; the attack feature embedding module is used for processing the preprocessed network state data by adopting a time sequence diagram neural network so as to automatically extract time sequence features in the network attack and identify an attack mode; the structural feature embedding module is used for learning topological structural features of the network based on the graph neural network; the deep reinforcement learning module is used for generating a network topology reconstruction strategy by adopting a Markov decision process according to the attack mode and the topological structure characteristics; and the network topology reconstruction module is used for executing a network topology reconstruction strategy and carrying out dynamic addition, deletion or reconnection operation on network nodes and edges. According to the method, a self-adaptive defense solution can be provided in the face of compound and multi-modal attacks, and the robustness and the survival rate of the network are improved.
Owner:BEIJING UNIV OF POSTS & TELECOMM

Dynamic trapping network deployment method and system based on Markov decision process

The invention provides a dynamic trapping network deployment method and system based on a Markov decision process, and relates to the technical field of network security. The method provided by the invention comprises the following steps: extracting TTP features from multi-source attack behavior data, mapping the TTP features into TTP feature vectors corresponding to attack steps, and constructing a TTP feature vector sequence according to an attack sequence; based on a Markov decision process model combined with multi-source threat intelligence, performing threat degree quantitative evaluation and sorting on the TTP feature vector sequence to obtain a sorted TTP feature vector sequence, and mapping the TTP feature vector sequence to a corresponding CVE number; based on the CVE serial number, selecting a honey point mirror image containing the corresponding vulnerability from a honey point warehouse; and based on the selected honey spot mirror image and the network defense demand, dynamically adjusting a honey spot deployment strategy and network topology configuration, and constructing a dynamic trapping network. According to the method, adaptive topological optimization from threat assessment to honey spot deployment is realized through the Markov decision process model.
Owner:GUANGZHOU UNIVERSITY

IP address and port hopping defense method based on reinforcement learning

PendingCN122394815AIp addressAttack
The application discloses an IP address and port hopping defense method RLAPH based on reinforcement learning. In view of the problems of relatively simple hopping strategy, single hopping dimension and high defense cost in the existing scheme, the application utilizes a reinforcement learning algorithm to perform cooperative hopping of IP addresses and ports, balances defense effect and system performance by designing a reasonable reward function, and reduces unnecessary resource consumption. In addition, considering that network security events have certain continuity and periodicity, the application utilizes a CNN to extract historical data features, can effectively cope with dynamic attacks with time sequence characteristics, and thus improves the accuracy of decision-making. The method comprises the steps of detection log aggregation, strategy generation, hopping execution and flow table updating. The application can be widely applied in cloud computing, edge computing and Internet of Things environments while effectively improving network defense capability and reducing resource consumption.
Owner:BEIJING UNIV OF POSTS & TELECOMM

Network defense method, device, apparatus and storage medium

This invention relates to the field of network security technology and discloses a network defense method, apparatus, device, and storage medium. The method is applied to a security defense system deployed in a network environment, where device nodes and honeypot nodes are deployed, and the device nodes deploy defense strategies. The method includes: acquiring reward information from the network environment based on the defense strategies, where the reward information represents the current attack losses after deploying the defense strategies; receiving attacker information from each honeypot node after inducing an attacker to launch an attack; and determining whether to redeploy the defense strategies based on the reward information and the attacker information. This invention combines the reward information from the network environment and the attacker information from the honeypot nodes to comprehensively determine whether to redeploy the defense strategies. Compared to the static defense strategies of existing technologies, the above method of this invention can flexibly respond to changing attack methods and effectively improve security defense efficiency.
Owner:PENG CHENG LAB

A network space confrontation knowledge graph construction method based on operatorization framework

The application relates to the technical field of network confrontation, and provides a network space confrontation knowledge graph construction method based on an operator framework, which comprises the following steps: mining an operator set in a network space, wherein the operator set comprises a first operator, a second operator and a third operator; the first operator is an identity operator, the second operator is a strong operator, and the third operator is a total bounded linear operator; performing convergence judgment on the second operator, combining the first operator and the third operator to form a target operator value framework; performing attack and defense in the network space based on the operator value framework, obtaining network attack and defense data; mapping and corresponding the network attack data and the network defense data to obtain a construction data set; constructing a network confrontation knowledge graph; and performing information confrontation control in the network space based on the network confrontation knowledge graph. The method can solve the technical problem that the key node confrontation effect is poor in the network confrontation process.
Owner:BEIJING CYBERYEON TECH CO LTD

System and method for detecting anomalies within an avionics and vetronics network

A method for detecting and attributing the cause of anomalies within a cyber-physical system such as in avionics or vetronics network is disclosed. The method comprises monitoring, via at least one processor, data of one or more components within the avionics and vetronics network in real time; determining, via the at least one processor, one or more anomalies from the monitored data using a condition-based maintenance model and a cyber-defense model; determining, via the at least one processor, whether the one or more anomalies is related to a cascading fault using the condition-based maintenance model and the cyber-defense model; determining, via the at least one processor, the one or more anomalies corresponding to a component failure or an evidence of the cyberattack; and generating, via the at least one processor, one or more alerts for a user associated with the one or more anomalies.
Owner:HONEYWELL INTERNATIONAL INC

Network node security measure mitigation deployment optimization method and system based on deep reinforcement learning

The present application belongs to the technical field of network security, and particularly relates to a network node security measure mitigation deployment optimization method and system based on deep reinforcement learning. The network node security measure mitigation deployment is converted into a multi-objective optimization problem by using a deep reinforcement learning mitigation measure model. The deep reinforcement learning mitigation measure model is based on a security knowledge base and establishes the relationship between attacks and defenses connected by vulnerabilities by using the security knowledge base. The problem space is constructed according to the action space, the state space and the reward function, and the mitigation deployment is optimized in the problem space by using the deep reinforcement learning method. The present application can comprehensively consider the importance weight of the deployment node, the deployment cost, the vulnerability repair and the attack effectiveness, establish a bridge between the vulnerability, the mitigation measure and the attack technology, and better maintain the decision of the mitigation action, and has potential in controlling the network defense cost of large organizations.
Owner:Chinese People's Liberation Army Cyberspace Force Information Engineering University