Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

50 results about "Network defense" patented technology

Network defense agent system based on large language model

The invention belongs to the field of network security, and particularly discloses a network defense agent system based on a large language model. Through the design of the sensing layer, the decision analysis layer and the action execution layer, comprehensive protection of network threats is realized. The sensing layer is responsible for collecting original information from multiple channels and converting the original information into standardized data; the decision analysis layer performs modeling and threat reasoning on attack behaviors, evaluates a risk level and predicts subsequent actions; and the action execution layer specifically executes defense operation according to the defense strategy scheme output by the decision analysis layer. In addition, the application also constructs a data set oriented to attack and defense confrontation, records a complete attack sequence, defense response and effect evaluation thereof, and provides a reliable basis for continuous learning of defense agents. Experimental results show that the framework provided by the invention is superior to the traditional method in the aspects of attack detection accuracy, attack chain identification and defense strategy generation, and has stronger adaptability and real-time response capability.
Owner:HUAZHONG NORMAL UNIV +1

Network security situation awareness method and system based on deep learning

The invention discloses a network security situation awareness method and system based on deep learning, and the method comprises the steps: generating a time-space sequence data set through integrating a multi-source flow log and a behavior record, extracting the abnormal signal intensity, and generating an embedded vector set representing attack multidimensional through employing a graph representation learning method; and when the abnormal signal intensity exceeds a threshold value, mining time sequence relevance through a sequence analysis model, judging a hidden threat evolution path, updating complex attack chain representation in real time by utilizing a dynamic tracking mechanism, generating future threat probability distribution by fusing a risk prediction method, and determining a high-risk threat priority sequence. For high-risk threats, an early warning mechanism is activated through infrastructure influence assessment, a safety guarantee protocol is integrated, a protection layer is applied, and enhanced network defense configuration is generated. According to the embodiment, through integration of spatio-temporal data fusion, dynamic threat tracking and risk prediction, the detection precision and response speed of hidden threats are remarkably improved, and the safety of key infrastructures is guaranteed.
Owner:HUNAN JIEYIXIN TECH CO LTD

Power network distributed cooperative defense method, system and device based on graph neural network, and storage medium

The invention relates to the technical field of power network security protection, in particular to a power network distributed cooperative defense method, system and device based on a graph neural network and a storage medium. The method comprises the following steps of: constructing a multi-relation graph structure comprising a master station, a substation and terminal equipment, and extracting node local embedding and full-graph-level situation embedding by adopting a graph neural network; establishing a centralized evaluation network to carry out topological position differentiation evaluation, and constructing a distributed action execution network to realize localized defense decision; a centralized training and distributed execution mechanism is adopted, a global strategy is uniformly optimized in a training stage, and each node independently executes a defense action in an execution stage; strategy iteration optimization is carried out through defense execution feedback, and attack mode changes are dynamically adapted. The technical problems of insufficient topology utilization, high response time delay and weak adaptive capacity in traditional power network defense are solved.
Owner:GUIZHOU POWER GRID CO LTD

Firewall dynamic policy adaptation method and system based on big data

The invention discloses a firewall dynamic policy adaptation method and system based on big data, and the method comprises the steps: collecting multi-source heterogeneous data in a network, and constructing a dynamic network entity map in real time; processing the time sequence of the atlas by using a preset time sequence diagram attention network model to obtain a behavior fingerprint vector representing the behavior state of the entity, and calculating the risk score of the entity; when the risk score exceeds a risk threshold value, automatically generating a temporary security policy for managing and controlling the access behavior of the entity; and managing the life cycle of the temporary security policy, and automatically updating, renewing or cancelling according to the entity risk state change. According to the method, the network entity behavior baseline is constructed and the risk prediction is carried out, so that the conversion from passive defense to active defense is realized, the security policy can be automatically and accurately generated and managed, advanced persistent threats and zero-day attacks can be effectively coped with, and the self-adaptability and the intelligent level of network defense are improved.
Owner:HANGZHOU TAICHENG NETWORK TECH CO LTD

Network threat analysis method and system based on learning evolutionary game

PendingCN121485949AUser identity/authority verificationCyber threat intelligenceEngineering
According to the network threat analysis method and system based on the learning evolutionary game provided by the invention, the expected benefit of sharing is analyzed through modeling, quantitative analysis is carried out by adopting the learning evolutionary game, and a reasonable incentive strategy is obtained, so that the sharing and utilization efficiency of network threat intelligence is promoted; each entity enterprise inquires from the open community to obtain the required threat intelligence, analyzes the threat intelligence and deploys own network defense measures, so that the network security defense capability is improved, and the problems that in the prior art, the capability of providing a large number of resources is difficult, the data sharing and exchanging capability is weak, and a large number of continuous network attacks are difficult to defend are solved.
Owner:北京国瑞数智技术有限公司

An unmanned aerial vehicle data collection optimization method based on matrix completion and trust evaluation

PendingCN122373092AData packSimulation
This invention proposes an optimized method for drone data acquisition based on matrix completion and trust assessment, applicable to drone forensics in IoT network defense. First, in matrix completion, the sampling point locations and data packet acquisition times are constructed into a matrix, and matrix completion technology is used to recover all information and select sampling points. Second, in the drone flight trajectory, the selected sampling points and the Elite Ant Trail Optimization (EATO) algorithm are combined to optimize the drone's flight trajectory. Third, in the trust evolution mechanism, the comprehensive trust level of sensor nodes is obtained through dual evaluation by neighboring nodes and the drone. The proposed method can solve the security risks and resource consumption problems of data acquisition from IoT smart devices, effectively identify malicious nodes, optimize the accuracy of trust assessment, improve network security, and reduce drone energy consumption.
Owner:GUANGXI UNIV +1

Communication network defense processing method, storage medium and electronic device

PendingCN122348841AAttackSimulation
The application discloses a defense processing method of a communication network, a storage medium and an electronic device. It relates to the technical field of network security, and the method comprises the following steps: determining a plurality of initial attack resource quantities based on the respective corresponding traffic data of a plurality of device nodes in a target communication network within a preset time window; determining a plurality of initial defense resource quantities based on the plurality of initial attack resource quantities and the respective corresponding node importance degrees of the plurality of device nodes; determining a target function of the target communication network based on the plurality of initial attack resource quantities, the respective corresponding node importance degrees of the plurality of device nodes and the plurality of initial defense resource quantities; and optimizing the plurality of initial defense resource quantities to obtain a plurality of target defense resource quantities, with the maximum function value of the target function as the optimization target. The application solves the technical problem that, due to the fact that the related art does not comprehensively consider factors when facing a complex attack-defense scene, the adaptability of a defense strategy in an actual network environment is insufficient.
Owner:STATE GRID BEIJING ELECTRIC POWER CO +1

Methods and systems for efficient adaptive logging of cyber threat incidents

ActiveUS12603862B2Securing communicationData packCyber threat intelligence
A packet-filtering network appliance such as a threat intelligence gateway (TIG) protects TCP / IP networks from Internet threats by enforcing certain policies on in-transit packets that are crossing network boundaries. The policies are composed of packet filtering rules derived from cyber threat intelligence (CTI). Logs of rule-matching packets and their associated flows are sent to cyberanalysis applications located at security operations centers (SOCs) and operated by cyberanalysts. Some cyber threats / attacks, or incidents, are composed of many different flows occurring at a very high rate, which generates a flood of logs that may overwhelm computer, storage, network, and cyberanalysis resources, thereby compromising cyber defenses. The present disclosure describes incident logging, in which a single incident log efficiently incorporates the logs of the many flows that comprise the incident, thereby potentially reducing resource consumption while improving the informational / cyberanalytical value of the incident log for cyberanalysis when compared to the component flow logs. Incident logging vs. flow logging can be automatically and adaptively switched on or off depending on the combination of resource consumption and informational / cyberanalytical value.
Owner:CENTRIPETAL NETWORKS INC

A dynamic security defense method and system based on thermal migration and deep learning

ActiveCN116318779BAttackHoneypot
The application discloses a kind of dynamic security defense method and system based on thermal migration and deep learning, by preliminary discrimination of traffic using intrusion detection system, again using the malicious traffic detection module based on deep learning review and determine as malicious traffic, SDN controller forwards traffic to low interaction honeypot, when attack depth reaches critical point, the copy of normal host of timed snapshot is activated as high interaction honeypot by honeypot management system, then using redirection forwarding engine TCP_REPAIR agent switches connection to high interaction honeypot.The application relates to the field of network defense technology, uses the malicious traffic detection technology based on deep learning, accurately shunts encrypted or non-encrypted normal and malicious traffic, makes up the defect that traditional defense system can only detect non-encrypted traffic, simultaneously using TCP thermal migration technology, optimizes the shortcomings of long time consumption and non-concealed switching in traditional TCP connection switching process, effectively improves the dynamic defense capability of system and utilization rate and decoy capability of honeypot cluster.
Owner:GUILIN UNIV OF ELECTRONIC TECH

Method and system for implementing a service that simplifies network cyber defense capabilities

ActiveUS12665919B2Securing communicationCyber defenseEngineering
A method, system, and computer-readable storage medium for implementing a service that simplifies network cyber defense capabilities. The method includes: compiling a resource list of resources that exist within a computer network; compiling a cyber defense list of cyber defense mechanisms that exist within the computer network; evaluating the resources and the cyber defense mechanisms, against any applicable threats or vulnerabilities, to determine whether there are any threats to the computer network or any vulnerabilities to that network; and generating a visual indication of any of the computer network's threats or vulnerabilities. The resource list may include a resource configuration of the resources, and the cyber defense list may include a cyber defense configuration of the cyber defense mechanisms.
Owner:JPMORGAN CHASE BANK NA

Network defense detection method and device, equipment, storage medium and product thereof

The invention discloses a network defense detection method, device and equipment, a storage medium and a product thereof, and relates to the technical field of network security, the method is applied to a coprocessor module arranged in a terminal, the coprocessor module is used for network security testing, and the method comprises the following steps: monitoring a network service enabling event of the terminal, loading a corresponding attack script according to the started service to carry out a network security test; in the testing process, comparing a first transfer path of the protocol state expected by the attack script with a second transfer path of the protocol state actually executed by the main processor, and judging whether the first transfer path is consistent with the second transfer path or not; and if the first transfer path is not consistent with the second transfer path, determining that an exception exists in the test, and controlling a communication module of the terminal to repair the corresponding security hole. That is, the whole process from vulnerability identification to communication layer repair can be completed without depending on external network interaction, so that the autonomous defense capability of the Internet of Things terminal in a complex network environment is enhanced.
Owner:PANASONIC APPLIANCES (CHINA) CO LTD

Adaptive network defense and topology reconstruction system based on attack feature learning

The invention discloses a self-adaptive network defense and topology reconstruction system based on attack feature learning, and the system comprises a data collection and preprocessing module which is used for collecting network state data and attack information in real time, and carrying out the preprocessing of the collected data; the attack feature embedding module is used for processing the preprocessed network state data by adopting a time sequence diagram neural network so as to automatically extract time sequence features in the network attack and identify an attack mode; the structural feature embedding module is used for learning topological structural features of the network based on the graph neural network; the deep reinforcement learning module is used for generating a network topology reconstruction strategy by adopting a Markov decision process according to the attack mode and the topological structure characteristics; and the network topology reconstruction module is used for executing a network topology reconstruction strategy and carrying out dynamic addition, deletion or reconnection operation on network nodes and edges. According to the method, a self-adaptive defense solution can be provided in the face of compound and multi-modal attacks, and the robustness and the survival rate of the network are improved.
Owner:BEIJING UNIV OF POSTS & TELECOMM

Dynamic trapping network deployment method and system based on Markov decision process

The invention provides a dynamic trapping network deployment method and system based on a Markov decision process, and relates to the technical field of network security. The method provided by the invention comprises the following steps: extracting TTP features from multi-source attack behavior data, mapping the TTP features into TTP feature vectors corresponding to attack steps, and constructing a TTP feature vector sequence according to an attack sequence; based on a Markov decision process model combined with multi-source threat intelligence, performing threat degree quantitative evaluation and sorting on the TTP feature vector sequence to obtain a sorted TTP feature vector sequence, and mapping the TTP feature vector sequence to a corresponding CVE number; based on the CVE serial number, selecting a honey point mirror image containing the corresponding vulnerability from a honey point warehouse; and based on the selected honey spot mirror image and the network defense demand, dynamically adjusting a honey spot deployment strategy and network topology configuration, and constructing a dynamic trapping network. According to the method, adaptive topological optimization from threat assessment to honey spot deployment is realized through the Markov decision process model.
Owner:GUANGZHOU UNIVERSITY

IP address and port hopping defense method based on reinforcement learning

PendingCN122394815AIp addressAttack
The application discloses an IP address and port hopping defense method RLAPH based on reinforcement learning. In view of the problems of relatively simple hopping strategy, single hopping dimension and high defense cost in the existing scheme, the application utilizes a reinforcement learning algorithm to perform cooperative hopping of IP addresses and ports, balances defense effect and system performance by designing a reasonable reward function, and reduces unnecessary resource consumption. In addition, considering that network security events have certain continuity and periodicity, the application utilizes a CNN to extract historical data features, can effectively cope with dynamic attacks with time sequence characteristics, and thus improves the accuracy of decision-making. The method comprises the steps of detection log aggregation, strategy generation, hopping execution and flow table updating. The application can be widely applied in cloud computing, edge computing and Internet of Things environments while effectively improving network defense capability and reducing resource consumption.
Owner:BEIJING UNIV OF POSTS & TELECOMM

Network defense method, device, apparatus and storage medium

This invention relates to the field of network security technology and discloses a network defense method, apparatus, device, and storage medium. The method is applied to a security defense system deployed in a network environment, where device nodes and honeypot nodes are deployed, and the device nodes deploy defense strategies. The method includes: acquiring reward information from the network environment based on the defense strategies, where the reward information represents the current attack losses after deploying the defense strategies; receiving attacker information from each honeypot node after inducing an attacker to launch an attack; and determining whether to redeploy the defense strategies based on the reward information and the attacker information. This invention combines the reward information from the network environment and the attacker information from the honeypot nodes to comprehensively determine whether to redeploy the defense strategies. Compared to the static defense strategies of existing technologies, the above method of this invention can flexibly respond to changing attack methods and effectively improve security defense efficiency.
Owner:PENG CHENG LAB

A network attack active defense strategy optimization method based on deep reinforcement learning

The application discloses a network attack active defense strategy optimization method based on deep reinforcement learning, which comprises the following steps: collecting multi-source data of network environment, performing feature clipping and white list feature reservation; performing normalization and coding processing to generate a security posture vector; constructing a multi-index reward function to generate an instant reward value and an event-level reward value; executing a double closed-loop mechanism through an improved PPO model to respectively output an instant strategy instruction and a long-term strategy parameter; performing multi-source evidence deliberation on the instant strategy instruction and the security posture vector, judging a key evidence loss condition, and obtaining an execution token; inputting a risk budget pool to perform resource quota checking, anti-jittering and cooling control; and optimizing parameters of the multi-index reward function through a causal account book. The application can realize rapid response and continuous optimization of various attack behaviors, balance defense effect and resource utilization rate, reduce false alarm and missed alarm rates, and improve the adaptability and stability of the network defense system.
Owner:QIAN XINGCHENG NETWORK SECURITY TECH (HUNAN) CO LTD

A network defense method, device, apparatus and medium

The application relates to the technical field of network security, in particular to a network defense method and device, equipment and medium, which are used for effectively coping with changing network threats and improving network defense effect. The method comprises the following steps: constructing a deep reinforcement learning (DRL) model, setting a state space and an action space of the DRL model, and constructing a reward function based on key defense indexes of a network system; training the DRL model by using a soft actor-critic (SAC) algorithm; obtaining current network state information of the network system, inputting the current network state information into the trained DRL model, obtaining optimal network defense measures, and executing the optimal network defense measures. In this way, the deep reinforcement learning technology can be used to dynamically adjust the protection mechanism to cope with the changing network threats, and in addition, when a potential threat is detected, the effective network defense measures are automatically executed, so that the system can be switched from passive monitoring to active defense.
Owner:CHINA TELECOM NETWORK SECURITY TECH CO LTD

A network defense method, device, electronic device, and storage medium

The embodiment of the application is suitable for the technical field of computers, and provides a network defense method and device, electronic equipment and a storage medium, wherein the network defense method is applied to a honeypot system, and the method comprises the following steps: in the case that the honeypot system and a client establish a transport layer connection, determining whether to send a first packet message to the client; if the first packet message is sent to the client, obtaining an access request of the client after the first packet message is sent to the client; and closing the transport layer connection between the honeypot system and the client.
Owner:SHENZHEN SHENXIN INFORMATION SECURITY CO LTD

Network security intelligent operation management system and method

The invention provides a network security intelligent operation management system and method, and relates to the technical field of network security, and the system comprises an asset management module which is used for collecting asset list data; the security event monitoring module is used for collecting security log and event information, constructing an exception identification model, inputting the security log and event information and asset list data into the exception identification model, and outputting a predicted security result; the decision response module is used for determining the severity level of the predicted safety result and selecting a strategy operation from a preset strategy library; the decision execution module is used for executing strategy operation. According to the method, related data is acquired through multi-source data, a related knowledge graph is constructed, key assets, abnormal events and potential threats are analyzed and identified, vulnerability risk assessment and automatic strategy selection and execution are realized, the response speed and accuracy of security events are improved, manual dependence and missing report and false report risks are reduced, and the security risk is improved. And the network defense capability and the safety operation intelligence level are enhanced.
Owner:SHANDONG SHUYUE INFORMATION TECHNOLOGY CO LTD

Comprehensive cyberdefense technology

PCT designated stage expiredWO2026117224A2Mathematical modelsArtificial lifeCyber-attackSystem controller
System and method of cyberattack detection and intervention for controllers in an operational technology environment provides one or more AI-based cyberattack detection modules combined with at least one conventional intrusion detection module. Semi-automatic rule engine automatically generates rules for rule based countermeasures. Rule-based countermeasure module triggers a rule-based countermeasure signal to a power system controller in response to a detected cyberattack as a first level countermeasure. AI-based countermeasure module triggers an AI-based countermeasure signal to a power system controller as a second level countermeasure.
Owner:SIEMENS CORP

Hybrid adaptive network

PendingJP2026010088ATransmissionCommunications systemCyber defense
To provide a method for managing a hybrid adaptive network (HAN) and a HAN manager for using a plurality of independent communication networks as an integrated communication system.SOLUTION: A HAN includes multiple communication networks that a user terminal can simultaneously access, enabling the user terminal to seamlessly roam across the multiple communication networks and increasing the functionality and resiliency of the user terminal by providing simultaneous access to the multiple communication networks. The communication networks operate over multiple orbital regions and across multiple frequency bands, provide independent ground infrastructure, and / or implement different network management and cyber defense, thereby providing inherent diversity and eliminating single points of failure and / or targets of attack.SELECTED DRAWING: Figure 1
Owner:VIASAT INC

A multi-modal optical communication module with cyber defense capabilities

The application discloses a kind of multi-modal optical communication modules with network defense capability, it is related to transmission technical field, solve optical communication module defense capability is insufficient, modal adaptability is poor, transmission is unstable and so on.The module is composed of shell, optical communication signal transceiver component, multi-modal transmission component, network defense component, total controller, adopts layered installation, double mode drive, multi-modal multiplexing, uses photoelectric double-layer monitoring, national encryption algorithm, three-level defense linkage security protection means, improves transmission performance by dynamic routing switching and error code compensation, realizes whole module cooperation by modal routing collaborative scheduling, with the characteristics of iP65 protection and EMC compatibility, improve transmission rate, anti-interference ability and network security, transmission and defense collaborative optimization.
Owner:HUAQIAO UNIVERSITY

Network attack traffic trapping method, device, equipment, medium and product

The invention relates to a network attack traffic trapping method, device and equipment, a medium and a product. The method comprises the following steps: acquiring network attack traffic in a target network and an attack type of the network attack traffic; acquiring a data packet type of an original data packet corresponding to the network attack traffic; distributing a target trapping node for the network attack traffic according to the attack type and the data packet type; and trapping the network attack traffic by using the target trapping node. By adopting the method, the effectiveness of network defense can be improved.
Owner:ELECTRIC POWER RES INST CHINA SOUTHERN POWER GRID CO LTD +1

A method for identifying critical substations of power grid considering cyber-physical cross-domain attacks

The present application relates to the technical field of power system, specifically relates to a kind of power transmission system key station identification method considering network-physical cross-domain attack, comprising the following steps: S1, the defense measure information of target substation is obtained: network defense measure configuration condition is obtained;S2, network attack path is built: according to the actual defense situation of substation, network attack path is proposed;S3, attack cost quantitative analysis: the attack cost paid by attacker in attack path is quantified;S4, attack cost clustering: attack cost is clustered;S5, attack optimization model is established: double-layer optimization model is established;S6, identification key station: double-layer optimization model is solved, finds system fragile station node, and power transmission system key station identification is carried out;The present application can help power transmission system to identify high-risk station in advance, optimize defense resource configuration, improve the ability of power grid to resist cross-domain attack.
Owner:NORTH CHINA ELECTRIC POWER UNIV

Endpoint agent and system

The endpoint agent detects a cyber threat on an end-point computing device. The endpoint agent on the computing device has a communications module that communicates with a cyber defense appliance. A collections module monitors and collects pattern of life data on processes executing on the end-point computing-device and users of the end-point computing-device. The communications module sends the pattern of life data to the cyber defense appliance installed on a network. The cyber defense appliance at least contains one or more machine-learning models to analyze the pattern of life data for each endpoint agent connected to that cyber defense appliance. The endpoint agent and the cyber defense appliance may trigger one or more actions to be autonomously taken to contain a detected cyber threat when a cyber-threat risk score is indicative of a likelihood of a cyber-threat is equal to or above an actionable threshold.
Owner:DARKTRACE HLDG LTD

Multi-agent dynamic defense game method and system based on federal reinforcement learning

The invention discloses a multi-agent dynamic defense game method and system based on federal reinforcement learning, and relates to the technical field of information security. The method comprises the following steps: modeling a distributed network defense scene into a multi-agent-based partially observable Markov environment, defining a seven-tuple environment model comprising an agent set, a global state space, a local observation space, an action space, a state transfer function, an observation function and a reward function, and designing a layered mixed reward function; and constructing a hierarchical collaborative defense architecture based on federal reinforcement learning, and executing a closed-loop online dynamic defense process based on the defense architecture. Distributed training and real-time decision are executed through the local agent layer, intra-group model encryption aggregation is performed through the edge layer, and global meta-strategy generation and dynamic role allocation are completed through the central layer. According to the architecture, communication overhead is reduced, single-point failure is avoided, original data privacy of each node is effectively protected, and efficient adaptive strategy learning and dynamic game collaboration can be realized.
Owner:SHENZHEN Y& D ELECTRONICS CO LTD

A cyber defense information analysis system and apparatus

PendingCN122268679ASecuring communicationInformation analysisCyber defense
This application relates to the field of network security technology and discloses a network defense information analysis system and device. The system collects network traffic data, firewall operation data, and network topology data to calculate the attack traffic impact intensity, attack traffic threat coefficient, and network defense capability attenuation. It then uses a geometric average of the attack traffic impact intensity and attack traffic threat coefficient, combined with the exponential amplification effect of the network defense capability attenuation, to map and obtain an overall network defense risk index. A quadratic exponential smoothing method is used to predict the risk index and fit the risk change slope. Based on the risk index and its change slope, a targeted network defense optimization scheme is generated. This application uses nonlinear coupling to characterize the interaction between attack pressure and defense vulnerability, achieving objective quantification and trend prediction of the overall network defense capability, thus improving the initiative and effectiveness of network defense.
Owner:NANJING VOCATIONAL UNIV OF IND TECH +1

Multi-mode optical communication module with network defense capability

The invention discloses a multi-mode optical communication module with network defense capability, relates to the technical field of transmission, and solves the problems that the optical communication module is insufficient in defense capability, poor in mode adaptability, unstable in transmission and the like. The module is composed of a shell, an optical communication signal receiving and transmitting assembly, a multi-mode transmission assembly, a network defense assembly and a master controller, the security protection means of layered installation, dual-mode driving and multi-mode multiplexing are adopted, photoelectric double-layer monitoring, cryptographic algorithm encryption and three-level defense linkage are adopted, and the transmission performance is improved through dynamic route switching and error code compensation. All-module collaboration is realized through modal routing collaborative scheduling, the system has the characteristics of iP65 protection and EMC compatibility, the transmission rate, the anti-interference capability and the network security are improved, and transmission and defense collaborative optimization is realized.
Owner:HUAQIAO UNIVERSITY

Attack event portrait analysis and recognition device and method based on knowledge graph

The invention discloses an attack event portrait analysis and recognition device and method based on a knowledge graph, and the device comprises an analysis and recognition device which is internally provided with a result display module, an analysis and recognition module, an unknown attribute analysis module, a safety response module, and a portrait construction module. According to the method, network security ontology knowledge which is relatively mature in research at present is utilized to construct a network defense knowledge graph with relatively comprehensive knowledge coverage, discrete threats, vulnerability and asset knowledge are integrated into a highly-associated knowledge system, complete knowledge support is provided for attack prediction, and the attack prediction efficiency is improved. According to the method, a path sorting algorithm with high prediction precision and high prediction result interpretability is selected, a relation path between an attacker entity and a target equipment entity is extracted as a feature, the attack is predicted more comprehensively, the influence of vulnerability unknown and expert knowledge one-sidedness is effectively overcome, the prediction accuracy is improved, and the prediction efficiency is improved. And support is provided for the interpretability of the prediction result.
Owner:STATE GRID TIANJIN ELECTRIC POWER COMPANY +1