Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

308 results about "Network isolation" patented technology

Isolation network. A network inserted in a circuit or transmission line to prevent interaction between circuits on each side of the insertion point.

Traffic anomaly detection and network security reinforcement method for full data center

The invention relates to a traffic anomaly detection and network security reinforcement method for a full data center, and the method comprises the steps: achieving the precise recognition and active blocking of an attack chain through the real-time collection of full network traffic, the construction of a multi-dimensional time sequence model based on historical attack chain features, and the combination of a dynamic judgment threshold value and spatial and temporal distribution feature analysis. The method specifically comprises the steps of analyzing traffic in real time to generate an attack chain feature sequence; performing clustering and correlation analysis based on the multi-dimensional time sequence model; dynamically adjusting the monitoring density to focus the high-risk area; and generating a threat blocking instruction and executing network isolation. Aiming at the problems of high attack chain omission ratio, resource contention conflict and insufficient dynamic defense capability caused by dependence on a static rule and a fixed threshold value in the traditional scheme, the method solves the problem of weak perception capability of the traditional technology on a complex attack chain, remarkably reduces the omission rate and the error blocking rate, guarantees the service continuity through dynamic resource scheduling, and improves the service performance of the system. The method is suitable for real-time security protection of a large-scale data center.
Owner:WEIHAI OCEAN VOCATIONAL COLLEGE +1

Power disaster recovery system-oriented micropatch non-inductive deployment engine and resource scheduling method, system, equipment and medium

The invention relates to the technical field of power monitoring system network security and real-time micropatch hot deployment, and discloses a power disaster recovery system-oriented micropatch non-inductive deployment engine, a resource scheduling method, a system, equipment and a medium, and the method comprises the steps: capturing system events through a kernel eBPF probe, and carrying out feature extraction and model reasoning; generating and transmitting an encrypted scheduling token; loading and verifying a patch fragment by a patch agent, inserting a jump instruction through a kernel interface to redirect an execution stream, and maintaining multi-kernel cache consistency; fusing multi-source telemetry data to carry out fusing judgment, realizing network isolation and calling a key service to cancel a key; and collecting runtime indexes and performing trend prediction, triggering a recovery or rollback operation according to a result, and storing an operation result and data through a block chain. According to the method, through combination of deep fusion of multi-source heterogeneous data, dynamic reasoning of a knowledge graph and strategy optimization of reinforcement learning, efficient perception and defense of a complex attack scene of a digital power grid are realized.
Owner:GUIZHOU POWER GRID CO LTD

Information security risk management method and management system

PendingCN120528623AUser identity/authority verificationShardInformation security risk management
The invention provides an information security risk management method and management system. The system is composed of four core modules: a multi-modal data acquisition layer: probes deployed at a terminal and a server support heterogeneous data acquisition of network traffic, operation logs and an API (Application Program Interface) call chain; according to the block chain log storage layer, a private chain is constructed based on an improved BFT consensus algorithm, and each block comprises a timestamp hash value and a preorder block fingerprint; the dynamic risk assessment engine adopts an LSTM-Transform hybrid neural network, and input dimensions comprise a user behavior baseline, a vulnerability library version and threat intelligence feed; and the intelligent response decision module is used for integrating a reinforcement learning algorithm, automatically generating a disposal strategy and triggering the SDN controller to execute network isolation. According to the method, a local chain-alliance chain-audit chain three-level structure is applied to data island treatment and data integration in organization, the problem of internal data fragmentation is solved through the local chain structure, unified storage and rapid source tracing of heterogeneous logs are achieved, and data authenticity and time sequence integrity are ensured.
Owner:KUNSHAN HANHAI INFORMATION TECH CO LTD

Power grid intrusion detection system based on artificial intelligence

The invention relates to the technical field of data processing, and discloses an artificial intelligence-based power grid intrusion detection system, which comprises a three-dimensional data cube construction module, a three-dimensional data cube feature extraction module, a feature fusion module, an attack probability prediction module, an attack credibility evaluation module and an intrusion protection module, aligning timestamps among the communication flow, the equipment state and the node topological relation of the power grid to generate a three-dimensional data cube of the power grid; abnormal node propagation characteristics and a flow time sequence mode are extracted; fusing the abnormal node propagation features and the time features of the flow time sequence mode through a cross-channel attention mechanism to obtain a fused feature vector; inputting the fusion feature vector into a full connection layer to obtain an attack probability; when the attack probability exceeds a preset threshold value, starting a sandbox verification process, and generating an attack credibility score; and issuing a network isolation and channel switching instruction based on the attack credibility score. The accuracy of power grid intrusion detection can be improved.
Owner:GUIZHOU POWER GRID CO LTD

Distributed medical equipment management platform and method based on zero-trust network

The embodiment of the invention provides a distributed medical equipment management platform and method based on a zero-trust network. In the distributed medical equipment management platform based on the zero-trust network, an edge trusted access module adopts a hardware root of trust mechanism, so that equipment accessed for the first time is connected to a temporary supply network isolated from a medical core network, and a zero-trust security normal form is followed; the distributed trust anchor point cluster constructs a distributed identity verification network based on federated learning, and the access pre-authorization authority is verified through a device distributed identity identification (DID); the dynamic permission arrangement engine injects an attribute-based access control strategy, generates a permission token in combination with network micro-segmentation, and realizes two-way encryption communication between the equipment and a target service; the intelligent isolation gateway cuts off temporary connection through a software defined network technology and sends a network access state proof through a block chain mechanism, and edge module initialization is executed by a trusted node outside the medical cloud.
Owner:GENERAL HOSPITAL OF PLA

Communication method, device and system and electronic equipment

The invention provides a communication method, device and system and electronic equipment, and relates to the technical field of network communication. The communication method comprises the following steps: executing an intelligent network card access network judgment operation to obtain a judgment result; when it is detected that the judgment result is access, an access request is sent to the switch, so that the switch broadcasts the access request to the intelligent network card located in the virtual local area network to which the static address of the target server substrate management controller belongs, and then the target intelligent network card responds to the access request and sends the access request to the switch. And performing network communication with the target server baseboard management controller through the static address of the target intelligent network card. The switch broadcasts the access request to the intelligent network card in the virtual local area network to which the static address of the substrate management controller of the target server belongs, which is equivalent to network isolation, so that network conflicts can be effectively avoided.
Owner:INSPUR SUZHOU INTELLIGENT TECH CO LTD

Network isolation system supporting multi-dimensional auditing

The invention relates to the technical field of network security, and discloses a network isolation system supporting multi-dimensional auditing, which comprises an access control module, a security isolation module, an auditing analysis module and a management platform module, the access control module is used for carrying out identity verification and protocol legality verification on the access request; the security isolation module is connected with the access control module and is used for performing protocol stripping and content cleaning on the verified data stream; and the auditing analysis module is in bidirectional communication with the security isolation module and the management platform module, and is used for collecting multi-dimensional auditing data pieces of the network layer, the application layer and the user behavior layer. According to the method, the abnormal access behavior is detected in real time, when high-frequency unconventional port access is detected, a risk early warning mechanism is triggered, an alarm event is generated, and the management platform is linked to dynamically adjust an access strategy, so that quick response and active defense to potential attack behaviors are realized, and the recognition and blocking capabilities of the system to complex threats are improved.
Owner:ZHENGZHOU UNIV

Vision-based cross-network interaction method and system

The invention provides a vision-based cross-network interaction method and system, and relates to the technical field of intelligent interaction, and the method comprises the steps: obtaining a visual interaction sequence, constructing multi-modal feature representation, achieving cross-domain semantic alignment, deconstructing visual information into a hierarchical control instruction set, and transmitting the hierarchical control instruction set to a target network environment for execution after security classification. And a bidirectional mapping relation graph is constructed to realize incremental optimization. According to the method, semantic bridging between heterogeneous networks can be established, the cross-domain control precision is improved, and meanwhile safe interaction in a network isolation environment is guaranteed.
Owner:ZHONGTIAN ZHILING (BEIJING) TECH CO LTD

Article label anti-counterfeiting authentication method and system and computer equipment

The invention relates to an article label anti-counterfeiting authentication method and system and computer equipment. Comprising the following steps: reading first label information containing an identification area, a coding area and a password area through an external network base station to realize data preliminary verification and label authentication; and the second label information only containing the coding area is read by the intranet base station for re-verification, so that data multiple verification and anti-counterfeiting verification are provided for electronic label data interaction in a network isolation environment, information comprehensiveness and security are considered, the accuracy and reliability of target object identification are improved, and the user experience is improved. And meanwhile, data security is guaranteed through partition information management.
Owner:CHANGSHA YINGXIN SEMICONDUCTOR TECHNOLOGY CO LTD

Secure sharing system for external equipment between internal and external network equipment

The invention provides an external equipment security sharing system between internal and external network equipment. The external equipment security sharing system comprises a control signal processor used for securely transmitting a control instruction of external HID equipment between the equipment; the control signal processor is respectively connected with an external computer host connected to an external network and an internal computer host connected to an internal network and isolated from the external network, and a control instruction of external HID equipment received by the external computer host is safely transmitted to the internal computer host through the control signal processor; and hardware isolation, protocol conversion, data encryption and watermark addition are adopted, so that the data security of an internal computer host is ensured. The data security of the internal computer host can be effectively ensured while the internal computer host and the external computer host share the external equipment.
Owner:GUANGZHOU YAQINGDA INTELLIGENT SYST CO LTD

Dynamic mapping of networks to multi-tenanted BGP servers

The present technology pertains to receiving, by a multi-tenanted cloud-native headend, network traffic from a source that is directed to a destination within a network of a first tenant, where the network traffic is routed using BGP over a multi-tenanted BGP network, where the multi-tenanted BGP network utilizes route isolation to isolate the network of the first tenant from networks of other tenants making use of the multi-tenanted BGP network, mapping the received network traffic based on at least a source IP, source port, and virtual network interface (VNI) to a port associated with the network of the first tenant over the isolated BGP route, where the mapping is a stateful mapping, where the mapping is also potentially based on other information associated with the network traffic, and directing the received network traffic to a local address in the network of the first tenant.
Owner:CISCO TECHNOLOGY INC

Anode assembly workshop three-dimensional visual management system and method based on digital twinning

The invention discloses a digital twinning-based three-dimensional visual management system and a digital twinning-based three-dimensional visual management method for an anode assembly workshop. The system comprises a triple binding index module, a unified time axis alignment module, a view cone inverse solution positioning module, a safety linkage arrangement module and a resume playback module, and is provided with a process template library and a network isolation / main / standby module. Three-dimensional positioning and PTZ linkage of an AI / threshold event are realized by establishing mapping of a three-dimensional object, a camera and a PLC point location; the batch / bracket / station events, the PLC time sequence and the video slices are indexed in a unified mode; shadow verification, interlocking check, instruction issuing, read-back and video consistency confirmation and trace leaving are executed according to the process, and a safe closed loop from warning to disposal is formed. The method comprises the steps of access and calibration, triple binding, time axis alignment, event positioning and stream taking, linkage processing and resume filing. The positioning and handling efficiency can be improved, the misoperation risk is reduced, and cross-production-line reuse and tracing evidence obtaining are supported.
Owner:QINGTONGXIA ALUMINUM GRP

AI-powered cybersecurity system for regulatory compliance in energy distribution

A system for AI-supported cybersecurity and regulatory compliance in energy distribution networks, consisting of: a hardware-embedded data acquisition module configured to intercept, capture, and time-stamp operational data streams and to control data traffic from SCADA (Supervisory Control and Data Acquisition) systems, AMI (Advanced Metering Infrastructure) systems, and energy management systems (EMS) via multiple communication protocols without operational latency; an FPGA-based deep packet inspection unit coupled with the data acquisition module, wherein the FPGA firmware is configured to perform line rate filtering, protocol decomposition and metadata extraction of the acquired data and forwards preprocessed packet data to an AI processing unit; an AI processing unit consisting of a multi-core central processing unit (CPU), a dedicated AI accelerator selected from a graphics processing unit (GPU) or a tensor processing unit (TPU), and a volatile memory buffer; a response orchestration module that is communicatively coupled with network management devices and operations controllers, wherein the response orchestration module is configured to perform automated security and compliance remediation measures, including network isolation of compromised segments, enforcement of protocol encryption, and privilege revocation; and an immutable audit logging subsystem configured to record all detected events, compliance assessments, and corrective actions in a blockchain-based distributed ledger, with each log entry cryptographically anchored with a secure hash value and digitally signed with keys stored in a secure hardware enclave.
Owner:ALIF MUHAMMAD +11

Control method for under-voltage tripping and voltage detection closing for low-voltage switch

The invention discloses a control method for under-voltage tripping and voltage detection closing for a low-voltage switch, and relates to the technical field of power distribution automation. The problems of function separation, low detection precision, poor anti-interference capability and inconvenient maintenance in the prior art are solved. The method comprises the following steps: S1, acquiring a high-precision digital voltage through a voltage transformer, a voltage division network, an isolation amplifier and a 24-bit delta sigma ADC; s2, interference is suppressed by combining temperature compensation, FIR filtering, median filtering and an oversampling integration algorithm; s3, comparing the real-time voltage with a tripping / closing threshold value which can be configured online in parallel; s4 / S5, triggering a zero-crossing short pulse to drive opening / closing based on the threshold value and the time delay; s6, performing parallel fault monitoring, shielding misoperation and uploading fault data; according to the invention, the detection precision, the anti-interference capability and the operation and maintenance efficiency of the system are obviously improved.
Owner:PINGDINGSHAN PINGGAO-YASKAWA SWITCH APP CO LTD

Multi-tenant API key authentication and resource isolation system in containerized environment

The invention discloses a multi-tenant API key authentication and resource isolation system in a containerized environment, and relates to the field of containerized multi-tenant authentication. Comprising an authentication authorization layer, a resource management and control layer and a security isolation layer. The authentication authorization layer comprises a multi-tenant authentication engine, an API key verification sub-module, a tenant identity recognition sub-module, an authority cascade verification sub-module and a dynamic authority calculation sub-module. And the resource management and control layer comprises a resource quota manager, a dynamic quota allocation sub-module, a real-time use monitoring sub-module, a threshold alarm control sub-module and an elastic capacity expansion and contraction sub-module. The security isolation layer comprises a multi-dimensional isolation engine, a container network isolation sub-module, a storage space isolation sub-module, a process permission isolation sub-module and a system call filtering sub-module; deep fusion of API authentication and container resource control is realized, a dynamic resource quota management mechanism based on tenant identities is established, and fine-grained API authority control and resource use limitation are provided.
Owner:CHINA IND INTERNET RES INST

Multi-level data cleaning method for nuclear power industry

The invention belongs to the technical field of nuclear power data processing, and particularly relates to a multi-level data cleaning method for the nuclear power industry. Comprising a first hierarchy data importing and preprocessing layer, and the first hierarchy is a basic unit for nuclear power multi-hierarchy data cleaning; the second level carries out local processing layer data processing, and the data subjected to secondary cleaning is recompressed, feature codes are extracted, and then the data are transmitted to the third level; or directly forwarding the unprocessed original compressed data; the third hierarchy carries out data processing of the platform layer in the data; and the fourth level performs data processing of the data application layer, and is responsible for performing persistent storage on the data according to a standardized format after the data is subjected to full-process cleaning, compression, feature extraction and desensitization processing. The method has the beneficial effects that the method is specially customized for the nuclear power industry: special requirements of high confidentiality, network isolation, large data volume and the like of data in the nuclear power industry are fully considered, and a special cleaning and desensitization process is designed.
Owner:NUCLEAR POWER OPERATIONS RES INST (NPRI)

Cloud platform design method based on Docker container technology

The invention discloses a cloud platform design method based on a Docker container technology, and relates to the field of cloud computers. The method comprises the following steps: deploying a plurality of containerized target application services in a distributed management cluster, and respectively determining the number of container instances required by the plurality of target application services; for each target application service, distributing a plurality of container instances to different working nodes for operation according to a scheduling strategy and the number of the container instances; configuring a multi-level network isolation strategy for the plurality of target application services; constructing a label-based dynamic container instance scheduling strategy, and performing real-time scheduling on the container instances of the plurality of target application services through the dynamic container instance scheduling strategy; and copying the cluster management state among the plurality of management nodes in real time, and carrying out synchronization and regular backup on the application state of the running container instance, so that the running states of all nodes in the distributed management cluster are consistent. The method can improve the reliability of cloud platform design.
Owner:LIAONING PROVINCIAL COLLEGE OF COMM

Data transmission method and device between security domains, storage medium and electronic equipment

The invention discloses a data transmission method and device between security domains, a storage medium and electronic equipment. Relates to the field of data transmission, and the method comprises: in a front-end application of a first security domain, in response to an interaction request triggered by a user, generating a request message containing a unique identifier, and issuing the request message to a message queue service in the first security domain, the message queue service being used for a large model processing service in a second security domain, consuming the request message according to a pre-configured security access strategy, and writing response data of the large model into a shared cache service of a first security domain; and initiating a query request to the shared cache service to obtain response data corresponding to the interaction request from the shared cache service, and displaying the response data to the user through a user interface of the front-end application. The problem that data transmission efficiency is low when data transmission between security domains in a one-way network isolation environment is realized by depending on a manual or semi-automatic off-line ferry mode in the prior art is solved.
Owner:TRAVELSKY TECHNOLOGY LIMITED

Intranet data anti-leakage method based on zero trust and related device

The invention discloses an intranet data anti-leakage method based on zero trust and a related device, and belongs to the technical field of information technology and data security. The method comprises the following steps: identifying mainboard information of terminal equipment through a desk management module, limiting all unauthorized data external transmission paths, and only allowing internal white list software to be installed; an isolation wall of an intranet and an extranet is established through a network isolation module, only one network is allowed to exist at the same time, a client is deployed at a credit granting terminal and is bound with a credit granting account, and a gateway end verifies a user identity through a security center and gives a corresponding access right; the flow management and control module is used for limiting the intranet flow to only access the white list website; through an outgoing approval module, mail outgoing is allowed and file outgoing parameters are set only after approval is passed; and single management and control of an external transmission path of intranet data and blocking of a secret divulging behavior are realized. Through real-time control and safety supervision, file protection and leakage prevention of intranet data can be achieved, operation is convenient and fast, and applicability is achieved.
Owner:ZHUHAI TIANCHENG ADVANCED SEMICON TECH CO LTD

Time series data cross-gatekeeper two-way transmission method, device and equipment

The invention relates to the field of data transmission, and provides a time series data cross-gatekeeper two-way transmission method, device and equipment, and the method comprises the steps: configuring an Internet of Things database cluster and an isolation gatekeeper, and determining a configuration result; according to the configuration result, the sending end is started to package the time sequence data, a data packet containing redundancy check information is generated, and the redundancy check information comprises a double-length field and a check code; transmitting the packaged data packet to a receiving end through an isolation gatekeeper; after the receiving end receives the data packet, verifying the dual-length field and the check code, if the verification is passed, returning a success signal, otherwise, returning a failure signal; and if the sending end receives the failure signal, automatically retransmitting the data packet until a successful signal is received or a preset retry condition is met. The problem that in the prior art, cross-gatekeeper time sequence data transmission cannot meet the requirements for high safety and real-time performance at the same time is solved, and safe and reliable time sequence data two-way real-time transmission under the strict network isolation condition is achieved.
Owner:TIANMOU TECH (BEIJING) CO LTD +1

Computing power network isolation method and device of intelligent computing center cloud platform

The invention provides a computing power network isolation method and device for an intelligent computing center cloud platform, and relates to the technical field of intelligent computing centers, intelligent computing centers and computing power infrastructures, and the method comprises the steps: S1, obtaining first network boundary information; s2, configuring a network for the computing power of the intelligent computing center cloud platform based on the first network boundary information; and S3, according to the first network boundary information, the network is divided into at least two network isolation spaces according to network isolation objects, the network isolation objects comprise at least one of tenants, items, tasks, services, containers and virtual servers, and each network isolation space is configured with a corresponding logic network. In the invention, the network isolation space is divided for the computing power configuration logic network, and the first network boundary comprises the network boundary information of different granularities, so that the computing power of the intelligent computing center cloud platform can be subjected to network isolation according to multiple granularities, and the flexibility of network isolation can be improved.
Owner:DATACANVAS LTD

Whole-plant auxiliary network monitoring access processing method and system for IP conflict sub-control equipment

The invention relates to the technical field of industrial automation and control, and discloses a whole-plant auxiliary network monitoring access processing method and system for IP conflict sub-control equipment, and the method comprises the steps: accessing a data interface machine and a network switch into each independently operating electric precipitation upper computer of different sub-control systems; the monitoring data are read from the corresponding electric precipitation upper computer through the data interface machine; label name conversion is carried out on the monitoring data in the data interface machine, and the name duplication phenomenon of the monitoring data is eliminated; performing network isolation on conflicting IP addresses of the sub-control systems through a network switch to form an independent communication link; and uploading the monitoring data subjected to label conversion and network isolation to a database of the auxiliary network monitoring system to realize data integration of the sub-control system and the auxiliary network monitoring system. According to the method, adverse factors such as normal operation of the electric precipitation equipment in the implementation stage are overcome, and the purpose of accessing the electric precipitation monitoring data to the power plant auxiliary network monitoring system is safely achieved.
Owner:HUANENG PINGLIANG POWER GENERATION CO LTD

Automatic operation and maintenance method and system suitable for closed system

The invention provides an automatic operation and maintenance method and system suitable for a closed system. The technical problem that a traditional operation and maintenance scheme is difficult to apply due to network isolation and sample scarcity in closed environments such as finance and energy is solved. The method comprises the following steps: generating a unique and traceable migration identifier for all operation and maintenance data, models and reasoning results through a data and migration management module; quantitatively calculating a transferability score between the source domain and the target domain through a transferability evaluation module; an optimal model migration strategy is dynamically selected according to the mobility score, and efficient self-adaption of the model is achieved; closed-loop operation and maintenance are executed through a multi-agent cooperation system comprising detection, diagnosis and repair agents, and self-learning and self-optimization of the system are realized through small sample active learning and a knowledge base evolution mechanism. According to the method, rapid construction, continuous evolution and whole-process traceability of the artificial intelligence operation and maintenance capability in the closed system are realized, and the method has remarkable innovativeness and industrial application value.
Owner:CHINA ACADEMY OF INFORMATION & COMM

System for secure MCP-mediated tool use by AI agents and generative AI / LLM services in cloud-native distributed applications

A system (100) for the secure MCP-mediated use of tools by AI agents and generative AI / LLM services in cloud-native distributed applications, wherein the system (100) comprises: a KL agent interface (1) configured to receive natural language commands and application events from a variety of client applications and to generate appropriate tool call commands for one or more generative KL or Large Language Model (LLM) services; an MCP mediator service (2) that is configured to: (a) to convert the tool request requests into messages compatible with a model context protocol (MCP); and (b) to maintain the conversation context, including at least one of the following: user identity, tenant identity and application identity; a tool register (3) that stores a plurality of tool descriptions, each tool description defining at least a tool identifier, an input and output scheme, an endpoint location and allowed functions, wherein the tool register (3) is accessible to the MCP mediator service (2); a policy and security manager (4) configured to evaluate each MCP tool call against one or more security and access policies based on the conversation context and the corresponding tool description, and to issue a decision to allow, modify or block the tool call; a tool connector layer (5) comprising a plurality of tool adapters, each tool adapter being configured to communicate securely with a corresponding external tool, service or data source using credentials and permissions restricted according to the decision of the policy and security manager (4); an observation and audit manager (6) configured to record, for each tool call, at least a timestamp, the calling KL agent, the tool identifier, the policy decision, and a summary of the tool response, and to provide audit logs and metrics for monitoring and compliance purposes; and a cloud-native deployment controller (7) configured to provide the MCP mediator service (2), policy and security manager (4), tool connector layer (5) and observation and audit manager (6) as distributed microservices with network isolation between tenants in a cloud-native environment.
Owner:BHANDARWAR NILESH DNYANESHWAR REDMOND

Infrastructure and application management system based on cloud native technology

The invention discloses an infrastructure and application management system based on a cloud native technology, and the system comprises a command line tool which is used for carrying out the communication with a server through an MQTT protocol, and executing the cluster management operation; the multi-tenant private cloud cluster module is used for realizing resource isolation and quota management among tenants; the mirror image warehouse module is used for storing and managing application mirror images; the declarative management module is used for defining a resource expectation state through a YAML configuration file; the CI / CD assembly line module is used for automatically constructing, testing and deploying applications; the gateway resource scheduling module is responsible for load balancing and flow control; the user authorization and authentication module is used for realizing authority control based on an RBAC model; the security module comprises data encryption and network isolation; and the asset library management module is used for managing a program component and a platform library. By integrating a cloud native technology stack, a set of efficient, safe and extensible infrastructure and application management system is constructed, and the deployment efficiency and the operation and maintenance capability of enterprise-level applications are remarkably improved.
Owner:HEFEI TANOVO INFORMATION SECURITY TECH CO LTD

Server real-time monitoring and self-recovery method suitable for network isolation environment

The invention discloses a server real-time monitoring and self-recovery method suitable for a network isolation environment, and relates to the field of server operation maintenance, a plurality of servers and supervision equipment are located in a first network environment isolated from the outside, and the method comprises the following steps: constructing the supervision equipment which is used for monitoring hardware and software of the servers; the supervision equipment collects real-time state data of the server system when a fault occurs, and log data of the server system and resource use condition information of the server system are acquired and obtained; monitoring equipment analysis based on the collected and collected information to obtain a server fault evaluation result; the supervision equipment matches the server fault evaluation result with a fault library to obtain a first fault processing strategy; the supervision equipment executes the first fault processing strategy; according to the method, high-reliability fault monitoring and fault recovery of the server can be realized in a network isolation environment, the stability and the self-recovery capability of the server are improved, and the data security and the server system reliability are ensured.
Owner:CALCULATION AERODYNAMICS INST CHINA AERODYNAMICS RES & DEV CENT

Secret transmission security management system for secret-related electronic files

The invention relates to the technical field of secret-related electronic file transmission and management, and discloses a secret-related electronic file secret transmission safety management system which comprises a safety management system. The security management system comprises a hardware security support layer, a distributed security storage layer, a file full life cycle security management layer, a user identity authentication and behavior auditing layer, a security auditing layer and an emergency response layer. The confidential electronic file secret transmission security management system integrates a trusted computing chip, security boot firmware, a physical unclonable function (PUF) and an optical isolation technology through a hardware security support layer, is different from a traditional system which only depends on software protection, constructs a trusted execution environment from a hardware bottom layer, guarantees the operation credibility by using the trusted computing chip, and improves the security of the confidential electronic file. The secure boot firmware blocks illegal program loading, the PUF endows the hardware with a unique uncounterfeited identity, and the optical isolation realizes physical level network isolation, so that threats such as hardware tampering and physical attacks are radically defended.
Owner:BEIJING AEROSPACE NETWORK TECHNOLOGY CO LTD

Physical isolation network forward proxy method and device, and storage medium

The invention relates to the technical field of communication, and particularly provides a physically isolated network forward proxy method and device and a storage medium, a user domain deploys a Squid cascade proxy to receive a browser request, a rear TCP service node encapsulates traffic into a file, and the file is unidirectionally transmitted to a service domain through a gatekeeper. And after the service domain TCP client parses the file, the file is routed to the target service through the Squid forward proxy, so that safe cross-domain communication is realized. According to the invention, a forward proxy scheme in a network isolation environment is realized.
Owner:南京中孚信息技术有限公司

Industrial control safety cheating detection method and system based on container technology

The invention provides an industrial control security spoofing detection method and system based on a container technology, and relates to the technical field of industrial control network security, and the method comprises the steps: guiding an abnormal access request to a simulation service instance in a container environment, extracting an interactive operation to construct a multilayer directed graph, calculating a branch entropy value and a semantic deviation degree to form a feature vector, and carrying out the spoofing detection of the abnormal access request; and determining an attack stage based on the state transition matrix and the attack behavior knowledge base, controlling response data and implementing network isolation. The method can actively induce the attacker to expose the intention, accurately recognize the attack stage, and effectively protect the industrial control system from network attack.
Owner:BEIJING YUHONG XINAN TECHNOLOGY CO LTD

Power industrial control terminal network isolation method and system based on process security label binding

The application discloses a kind of power industrial control terminal network isolation method and system based on process security label binding;Belong to the technical field of power system network security, its operating steps include: decoupling physical network resources into independent partitions and mapping to independent user-mode network protocol stack instances;Through the bottom flow direction rule, the in-bound traffic is accurately delivered to the corresponding partition;Identify process security label at the application layer, establish the forced mapping of process and specific protocol stack instance and link;Through the controlled shared memory channel, realize the safe data interaction between partitions.The application realizes strong logical isolation on unified hardware, through the forced binding of process identity and network link, reduces the privilege promotion and horizontal penetration risk caused by traditional protocol stack sharing, while limiting the scope of failure impact, without relying on external physical isolation equipment, significantly improves the endogenous security protection capability of industrial control system network boundary.
Owner:NARI INFORMATION & COMM TECH