Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

8022 results about "Network security" patented technology

Network security consists of the policies and practices adopted to prevent and monitor unauthorized access, misuse, modification, or denial of a computer network and network-accessible resources. Network security involves the authorization of access to data in a network, which is controlled by the network administrator. Users choose or are assigned an ID and password or other authenticating information that allows them access to information and programs within their authority. Network security covers a variety of computer networks, both public and private, that are used in everyday jobs; conducting transactions and communications among businesses, government agencies and individuals. Networks can be private, such as within a company, and others which might be open to public access. Network security is involved in organizations, enterprises, and other types of institutions. It does as its title explains: it secures the network, as well as protecting and overseeing operations being done. The most common and simple way of protecting a network resource is by assigning it a unique name and a corresponding password.

System for detecting malicious nodes in a wireless sensor network and a method thereof

The present disclosure generally relates to a two-stage system for detecting malicious nodes in Wireless Sensor Networks (WSNs), enhancing network security and resilience. The system employs a distributed approach, leveraging Cluster Heads (CHs) and a central server for efficient and accurate detection. Initially, sensor nodes are monitored for comprehensive node and network metrics, statistically ranked by significance in identifying malicious behavior. CHs perform a resource-aware first-stage detection based on their resource weight, filtering potential threats locally. Results are then aggregated at a server for a second-stage analysis using a hybrid Machine Learning (ML) and Deep Learning (DL) approach. This advanced analysis, combined with statistically relevant metrics, significantly improves detection accuracy. By integrating resource-conscious CH operation with powerful server-side ML / DL, this system offers a scalable, energy-efficient, and highly effective solution for securing WSNs against malicious node attacks, surpassing traditional detection methods in both speed and precision.
Owner:KHASHAN OSAMA AHMED

Ai-based cybersecurity system and method thereof

An AI-based Cybersecurity System and Method enable real-time detection, analysis, and mitigation of cyber threats within computing networks using adaptive artificial intelligence. The system continuously monitors network traffic, extracts behavioral and contextual attributes, and applies deep learning-based inference to identify anomalous activities indicating security breaches. The method integrates several computational units, including a network monitoring unit, feature extraction unit, artificial intelligence processor, contextual reasoning processor, and decision synthesis unit, to compute a composite risk index quantifying threat likelihood and severity. A classification processor categorizes detected threats into types such as ransomware, phishing, or unauthorized access, while a mitigation control processor initiates automated response actions to isolate compromised nodes and restore network integrity. An adaptive learning processor updates AI models using feedback from confirmed incidents. This provides a scalable, self-evolving cybersecurity framework that minimizes human intervention and enhances resilience against dynamic and zero-day threats.
Owner:PELL REDDY RAJENDER REDDY

Analyzable anti-attack network security method and system based on AI unified model

The invention provides an analyzable anti-attack network security method and system based on an AI unified model. The method comprises the following steps: S1, carrying out attack source tracing and attack mode identification on an input data stream; s2, performing protocol structure analysis and grammar element extraction on the input data stream in a grammar verification layer, and starting a grammar rule matching process to obtain a grammar exception perception set; s3, fusing attack vector information on the basis of a grammar anomaly perception set in a semantic analysis layer, constructing a semantic relation graph, and outputting a semantic risk vector; s4, taking the semantic risk vector as input, combining a business scene, resource constraint and strategy preference, modeling a defense target, and outputting an optimal response path; and S5, forming a model evolution path based on local feedback and global collaboration. Through a three-layer full-information analysis mechanism and behavior feedback driving, interpretable recognition of attack intentions and collaborative optimization of defense paths are realized, attack recognition is comprehensive, response decision is accurate, and strategy evolution is controllable.
Owner:SHENZHEN CESTBON TECH CO

Network security big data state evaluation method based on pattern recognition

The invention relates to the technical field of network security, in particular to a network security big data state evaluation method based on pattern recognition, which comprises the following steps of: extracting multi-modal features from a network flow log, a system event log, a host behavior log and threat intelligence data, generating a feature matrix, performing feature dimensionality reduction by adopting an auto-encoding network, and obtaining a network security big data state evaluation result; carrying out attack behavior classification and abnormal mode identification in combination with unsupervised clustering and a graph neural network; constructing an attack transition probability matrix based on a Markov model; forming a time sequence attack chain; predicting an attack development trend; and a dynamic protection instruction is issued to the safety equipment. According to the method, the unknown attack detection capability can be improved, the time sequence attack traceability is enhanced, the security situation assessment is optimized, and the method is suitable for security situation awareness in cloud computing, industrial internet and large-scale network environments.
Owner:SHANDONG ENERGY GRP CO LTD +1

Network security protection method and system applied to regional digital and intelligent asset business

The invention provides a network security protection method and system applied to regional digital and intelligent asset businesses, and the method comprises the steps: collecting asset data flows of a plurality of asset business nodes in a target region, carrying out the threat feature extraction of the asset data flows based on a preset threat knowledge graph, and obtaining a threat feature extraction result; generating a dynamic threat feature vector corresponding to the asset service node; inputting the dynamic threat feature vector into a pre-trained dynamic protection model, and outputting a real-time protection strategy adaptive to the asset service node through a multi-layer decision network in the dynamic protection model; performing strategy execution on the network flow of the asset service node based on the real-time protection strategy, generating a strategy execution result and feeding back the strategy execution result to the dynamic protection model; and performing adaptive optimization on decision parameters of the dynamic protection model according to a strategy execution result, and generating an updated dynamic protection model for a protection decision of a next round of asset business nodes.
Owner:GUIZHOU ANRONG TECH DEV CO LTD +1

Industrial control network security advanced threat detection system fused with artificial intelligence

The invention provides an industrial control network security advanced threat detection system fused with artificial intelligence. The system comprises a multi-source data acquisition module, an intelligent analysis engine, a threat detection module, a dynamic defense module and a self-evolution learning system which perform data interaction in sequence. The industrial control network security advanced threat detection system fused with artificial intelligence realizes collaborative decision-making among the modules through a dynamic knowledge graph. Through multi-source data fusion, dynamic knowledge graph and lightweight model design, the core problems of protocol analysis, threat association, defense collaboration and model adaptability in the industrial control network security field are solved, and a full-stack protection system covering'perception-analysis-decision-response-evolution 'is constructed. The deep analysis capability of an industrial protocol is improved, the dynamic threat association analysis is broken through, the agility of a defense strategy is enhanced, and the feasibility of continuous optimization of a model is improved, so that a systematic solution is provided for advanced threat defense in a complex industrial control environment.
Owner:CPI NORTHEAST ENERGY SAVING TECH

Network threat multi-modal detection method based on large model

The invention discloses a network threat multi-modal detection method based on a large model, and belongs to the technical field of network security, and the method comprises the steps: collecting three types of heterogeneous data of NetFlow flow of a network layer, a system call chain sequence of a host layer and a protocol load of an application layer, and carrying out the desensitization processing and feature coding to generate a unified tensor format; the method comprises the following steps: through network security threat intelligence and MITRE ATTamp; performing supervision fine tuning on the large model by using a CK attack chain sample, and constructing a network threat identification special model; cross-device behavior characteristics are extracted through a model self-attention mechanism, and a dynamic behavior map is constructed; and finally, comprehensively evaluating an attack mode matching degree, a node vulnerability mean value, historical alarm association and an attack path risk by adopting a weighted fusion algorithm, and triggering a high-confidence alarm when a comprehensive score exceeds 0.8. According to the method, through multi-modal data fusion and dynamic graph analysis, the detection precision and response efficiency of the complex attack chain are improved.
Owner:SOUTHEAST UNIV

Exposure and Attack Surface Management Using a Data Fabric

The disclosed embodiments provide systems and methods for continuous exposure and attack surface management using a data fabric. Data from multiple heterogeneous cybersecurity sources, including vulnerability scanners, threat intelligence, cloud security tools, and endpoint monitoring systems, is ingested and integrated into a semantically harmonized representation, such as a security knowledge graph. This unified data model normalizes, correlates, and contextualizes diverse cybersecurity information, enabling comprehensive and real-time assessment of an organization's cybersecurity risk posture. Automated workflows trigger proactive remediation actions based on dynamically calculated exposure metrics. Additional embodiments leverage the same data fabric architecture to support specialized cybersecurity use cases, including unified vulnerability management (UVM), cyber asset attack surface management (CAASM), continuous threat exposure management (CTEM), and asset exposure management (AEM).
Owner:AVALOR TECH LTD

Risk management and control method and system based on real-time behavior analysis

The invention relates to a risk management and control method and system based on real-time behavior analysis, and the method comprises the steps: carrying out the structural processing of multi-source behavior data through lightweight protocol decoding and behavior label embedding, and constructing an original behavior data set of a user and an entity; extracting multi-dimensional behavior characteristics by using a sliding window analysis and sparse representation mechanism, and constructing a user behavior graph by combining graph embedding learning; constructing a time-sensitive behavior trend model through streaming modeling and an incremental learning strategy, identifying an abnormal evolution trajectory in real time, and introducing a dynamic risk threshold regulation and control mechanism; adopting a high-throughput flow data processing and fast similarity matching algorithm to construct a fusion discrimination model, giving risk levels to abnormal behaviors and classifying the abnormal behaviors; and finally, performing closed-loop optimization in combination with a historical treatment effect. The system has the advantages of high real-time performance, high calculation efficiency, adaptability to complex network environments and the like, and the network security protection capability can be effectively improved.
Owner:HAIER CONSUMER FINANCE CO LTD

Cloud desktop security access control method based on zero-trust architecture

The invention discloses a cloud desktop security access control method based on a zero-trust architecture, belongs to the technical field of network security, and is used for solving the problems of difficulty in hidden attack detection, cross-cloud attack chain breakage and conflict between security control and service continuity in a multi-cloud environment. Firstly, user identity attributes, session metadata and service call logs are aggregated, an identity-resource-behavior triple dynamic graph is constructed, cross-session association features are extracted, and a multi-dimensional behavior baseline is generated. And quantifying the access deviation degree based on the behavior baseline, triggering sensitive operation traceability analysis, constructing a time sequence risk propagation model, identifying latent attack features, predicting a penetration path and outputting a risk propagation coefficient. And finally, dynamically generating a process-level micro-isolation strategy according to a risk result, gradually adjusting the authority through a nonlinear authority attenuation function, inserting a secondary authentication node when unexpected resource jump is detected, reconstructing a communication white list, and realizing collaborative optimization of security protection and service continuity.
Owner:SHENZHEN HUITUO INFORMATION TECH CO LTD

Computer network information security monitoring method, system, equipment and medium

The invention relates to the technical field of network security, in particular to a computer network information security monitoring method, system and device and a medium, and the method comprises the steps: obtaining encrypted traffic data and application log data in a network environment, and constructing a space-time associated original data set based on the encrypted traffic data and the application log data; performing protocol analysis on the original data set with the time-space association to generate a protocol fingerprint feature vector; inputting the protocol fingerprint feature vector and the application log data into a preset heterogeneous multi-modal analysis model, and obtaining a multi-dimensional security situation assessment result containing a threat level and an attack path; and based on the multi-dimensional security situation assessment result, generating a dynamic defense strategy instruction set through a reinforcement learning algorithm, and issuing a strategy instruction to a network execution node in real time. The method and the device have the effects of realizing real-time accurate detection of encryption threats and constructing a dynamic defense system with balanced security and efficiency.
Owner:李俊磊 +1

Lightweight malicious network traffic detection method based on heterogeneous modal feature fusion

The invention discloses a lightweight malicious network traffic detection method based on heterogeneous modal feature fusion, and mainly solves the problems of low feature extraction efficiency and insufficient single modal feature representation of the existing method. Comprising the following steps: acquiring and optimizing a network flow data set, preprocessing the network flow data set, and extracting and generating spatial feature, time sequence feature and behavior pattern feature vectors; an improved self-attention mechanism network is constructed, a lightweight heterogeneous modal feature fusion model LMF is designed, multi-modal feature deep fusion is performed through dynamic weight distribution, a lightweight classification model is trained, and the model is utilized to detect network malicious traffic. Through the lightweight heterogeneous modal feature fusion model LMF and in combination with a dynamic weight distribution mechanism, spatial distribution, time sequence dependence and behavior semantic information of network traffic are deeply mined, data processing efficiency, malicious traffic detection accuracy and system robustness are improved, and the method is suitable for efficient malicious traffic identification and defense in the field of network security.
Owner:XIAN TECH UNIV

Distributed intelligent authentication method based on dynamic multi-modal fusion

A distributed intelligent authentication method based on dynamic multi-modal fusion relates to the field of network security, and adopts an alliance chain + DAG hybrid block chain architecture, combines a threshold signature to realize secret key fragment management, and switches among PBFT, Raft and probabilistic algorithms through a dynamic consensus mechanism to improve authentication efficiency. The multi-mode authentication module is based on a dynamic weight distribution algorithm, integrates biological characteristics, behavior analysis, equipment fingerprints and environmental factors, and combines an LSTM-GAN model and a quantum random number driven challenge-response mechanism to realize zero-trust verification under environmental perception. The session management module generates a session key by using a chaotic mapping algorithm. In the aspect of privacy protection, CKKS homomorphic encryption, zero-knowledge proof and attribute-based encryption are fused. According to the method, the block chain technology, the secure multi-party computing technology, the machine learning technology and the quantum cryptography technology are fused, and a high-performance, high-security and strong-privacy-protection distributed authentication solution is provided.
Owner:JINLING INST OF TECH

Network security analysis method and system based on big data

The invention relates to the technical field of network security, in particular to a network security analysis method and system based on big data. Comprising the following steps: collecting related multi-source heterogeneous data of a network, and carrying out standardized processing such as cleaning and de-noising; network analysis is carried out based on the preprocessed data, network traffic is analyzed in real time by using machine learning and deep learning algorithms, and abnormal conditions are detected; constructing a risk prediction model according to a network analysis result and related information, and predicting a future network security risk level; if the risk level exceeds the threshold value, determining a security event source and a responsibility subject through data tracing; and finally, generating a safety response strategy according to risk prediction and data traceability results, and performing disposal. The corresponding system covers the modules of data acquisition, preprocessing, network analysis, risk prediction, data tracing, security response and disposal and the like, and all the modules work cooperatively to form a complete network security analysis and guarantee system, so that the stable operation of the network system is guaranteed.
Owner:QINGDAO MOCHUANG FUTURE INTELLIGENT TECHNOLOGY CO LTD

AI dynamic secure transmission system based on SASE framework

The invention relates to the technical field of integration of artificial intelligence security and network security, and discloses an AI dynamic security transmission system based on an SASE framework, which realizes security access control based on AI dynamic identity verification through an SASE integration access module, acquires and predicts network performance change in real time by using a network state sensing module, and transmits the network performance change to a network server. Equipment, environment and data content are subjected to multi-dimensional analysis by means of a security risk assessment module, a quantitative risk score is generated, and a transmission protocol, parameters and encryption strength are dynamically adjusted according to a network state and the risk score by means of a dynamic transmission optimization module and a self-adaptive encryption module; the problem that safety protection and transmission efficiency are difficult to cooperate in a traditional architecture is effectively solved, low-delay and high-reliability data transmission service can be provided for AI application in a complex network environment, meanwhile, self-adaptive dynamic protection of the whole data transmission process is achieved, and data safety is comprehensively guaranteed.
Owner:BEIJING XINDA WANGAN INFORMATION TECH CO LTD

Industrial control network security service security guarantee system based on behavior analysis

The invention provides an industrial control network security service security guarantee system based on behavior analysis, which belongs to the technical field of industrial control network security, and comprises a multi-source data fusion acquisition module, a dynamic behavior modeling engine, a federal learning analysis cluster, an attack chain prediction module, a self-adaptive protection strategy executor and a model evolution feedback ring, wherein the multi-source data fusion acquisition module synchronously acquires industrial control network flow (including OPC UA / Modbus / DNP3 protocol analysis), equipment operation logs, user operation behavior fingerprints and physical interface state data, and the physical interface state data comprises electrical characteristic fluctuation monitoring of USB / network interfaces. According to the scheme, through multi-technology fusion and closed-loop design, the problems of static performance, single-dimension analysis defects and response lag of a traditional industrial control security scheme are effectively solved, a comprehensive protection system with dynamic modeling, intelligent decision making, privacy protection and continuous optimization is constructed, and the security and service reliability of an industrial control network are remarkably improved.
Owner:CPI NORTHEAST ENERGY SAVING TECH +1

APT attack chain reconstruction method based on knowledge graph and graph neural network

The invention discloses an APT attack chain reconstruction method based on a knowledge graph and a graph neural network, and belongs to the technical field of network security. Multi-source heterogeneous attack clues are subjected to advanced analysis by introducing a large language model, and time sequence enhanced knowledge graph representation and the deep learning ability of a graph convolution attention network are combined, so that the multi-source heterogeneous attack clues are reconstructed. The method promotes the efficient completion and dynamic reconstruction of the attack chain, and solves the problems that in the prior art, due to the problems of data sparsity, relation complexity, time sequence characteristics and the like, obvious limitation exists in the aspects of attack chain completion and inference, and a traditional method lacks the deep learning ability for the implicit relation in the attack chain. And thus, the problem of insufficient inference capability on unknown attack behaviors is solved.
Owner:SHENSI TECH CO LTD

Network security protection method and system based on information fusion

The invention provides a network security protection method and system based on information fusion, and the method comprises the steps: firstly obtaining a multi-source heterogeneous data set, which comprises a traffic interaction data unit, an equipment log data unit and a protocol analysis data unit, of a target network, then carrying out the time sequence correlation analysis of the traffic interaction data unit, and generating a traffic behavior feature set; and executing state mode analysis on the equipment log data unit to generate an equipment operation feature set, and executing semantic recognition on the protocol analysis data unit to generate a protocol analysis feature set. Then, on the basis of a multi-dimensional feature fusion rule, cross-dimensional feature fusion processing is carried out on the feature set, and a network situation feature set is generated; and calling a threat identification model to carry out threat identification on the set, generating a threat identification result set containing threat type identifiers and influence range parameters, and finally generating a security response strategy set according to the threat identification result and issuing the security response strategy set to a security control node to execute protection operation, thereby effectively improving the network security protection capability.
Owner:GUANGXI POWER GRID CORP

Graph-based network security event modeling method and system

The invention relates to a graph-based network security event modeling method and system, and the method comprises the steps: obtaining topological data and security policy information of a network where network security equipment is located, and carrying out the hierarchical construction of a knowledge graph, and obtaining a multi-layer security graph; acquiring real-time monitoring data of the network security equipment, and performing graph adversarial learning association with the multilayer security graph to obtain a dynamic evolution graph sequence; obtaining alarm data of the network security device, and performing anomaly detection on the multilayer security map to obtain an anomaly propagation situation; performing security assessment construction on the dynamic evolution diagram sequence and the abnormal propagation situation to obtain an initial security assessment scheme; performing alarm identification and attack link prediction on the alarm data to obtain a link prediction result; and performing evaluation and prediction on the initial security evaluation scheme and the link prediction result to obtain a security situation evaluation strategy. According to the invention, the security condition of the current network can be evaluated more accurately.
Owner:SHENZHEN TRUSTED CLOUD TECH CO LTD

Network security threat research and judgment method, system and equipment and storage medium

The invention discloses a network security threat research and judgment method, system and device and a storage medium, and the method comprises the following steps: S1, obtaining network traffic, terminal logs, application program interface calling records and threat intelligence data in real time, carrying out the standardized cleaning and format conversion of the data, and building a unified data lake; s2, matching, identifying and determining threats through a preset known threat feature library, constructing a normal behavior baseline by using an unsupervised learning algorithm, and marking suspicious events deviating from the baseline; s3, for the suspicious event marked in the step S2, mining a potential attack path and an attack intention by combining knowledge graph technology associated asset information, a historical attack chain and a homologous IP address; and S4, based on the attack success probability, the influence asset importance and the diffusion speed, calculating a threat level by adopting a fuzzy comprehensive evaluation model, and generating a research and judgment report containing disposal suggestions.
Owner:CRCC DEV GRP CO LTD +1

Network security analysis early warning system based on artificial intelligence

The invention discloses a network security analysis early warning system based on artificial intelligence, and the system comprises a data collection layer which captures full flow based on DPI, aggregates firewall logs, terminal behaviors and threat intelligence, and constructs a structured data pool; through TLS fingerprint identification of AI driving, the encrypted traffic is penetrated, and a sampling strategy is dynamically adjusted in combination with reinforcement learning. The intelligent analysis layer is used for carrying out cross validation on known threats and abnormal behaviors; the time sequence CNN extracts encrypted traffic features, and a novel threat detector is rapidly generated by using historical attack fragments in combination with a meta-learning framework; sHAP value driving dynamic feature selection and optimization feature vector input; the decision-making early warning layer is used for fusing multi-source features through a Bayesian network and generating 0-100 score risk scores; a self-adaptive threshold module is combined to adjust a score threshold in real time, and a high-risk event is pushed; the collaborative response layer is used for triggering a preset decision tree, deploying a GAN dynamic honeypot to trap an attacker and reversely tracing; the Neo4j visually restores the attack path, and blocking is executed after the threat is confirmed by a progressive response mechanism.
Owner:CHINA GEOLOGICAL SURVEY XINING NATURAL RESOURCES COMPREHENSIVE SURVEY CENT

Industrial network risk perception and collaborative early warning method based on dynamic risk map

The invention discloses an industrial network risk perception and collaborative early warning method based on a dynamic risk map, and relates to the technical field of industrial internet security, and the method comprises the steps: S1, multi-source perception deployment; s2, heterogeneous data fusion acquisition; s3, constructing a knowledge graph engine; s4, analyzing depth data; s5, performing dynamic risk assessment; and S6, intelligent early warning decision making. According to the industrial network risk perception and collaborative early warning method based on the dynamic risk map, through fusion perception of OT layer data such as equipment states and process parameters, the problems of single perception dimension, evaluation lagging and disjunction in the prior art are solved, the false alarm rate is extremely low, and the method is suitable for popularization and application. Particularly, a dynamic adjustment mechanism of a time-varying risk weight matrix is improved, novel attacks can be dynamically responded, meanwhile, cross-domain risk conduction analysis is achieved, the accuracy and response speed of industrial network security early warning are improved, and meanwhile a closed-loop mechanism of attack path prediction and disposal suggestions is constructed.
Owner:BEIJING ANDY TECH CO LTD

Financial network security defense method and system based on multiple Agents and dynamic large model

The invention discloses a financial network security defense method and system based on multiple Agents and a dynamic large model. A detection Agent is deployed in an edge layer, financial network node flow data and system logs are collected in real time, time sequence features are extracted through a lightweight convolutional network, and a preliminary anomaly score is generated. And the cloud layer constructs a decision Agent, receives the feature abstract transmitted by the edge node in an encrypted manner, inputs the feature abstract into a dynamic large model for multi-modal feature fusion, and outputs defense action probability distribution. And the intelligence Agent constructs a cross-institution federated learning network. And constructing a dynamic game engine, constructing a revenue matrix based on the attack cost and the defense revenue, solving a Nash equilibrium strategy, and generating an optimal defense instruction set. And dynamically allocating detection tasks according to the threat level and the edge computing power state. According to the method, efficient acquisition and analysis are realized, the abnormal behavior recognition capability is improved, support is provided for making a defense strategy, the defense strategy is optimized, and the intelligent, automatic and efficient levels of defense are improved.
Owner:HUAYING (SHANGHAI) INFORMATION TECH CO LTD

CAPEC vulnerability management system based on large language model

The invention discloses a CAPEC vulnerability management system based on a large language model, and belongs to the technical field of network security. The system comprises three modules: a vulnerability-CAPEC dynamic mapping module jointly encodes vulnerability description and code context through a bimodal large language model, accurately associates vulnerability logic with a CAPEC attack mode in combination with comparative learning and knowledge graph construction, and breaks through semantic limitation of traditional rule matching; the adversarial repair code generation module is used for generating high-robustness repair codes through adversarial training and syntax tree verification by fusing CAPEC relieving suggestions and code features on the basis of the association result, so that the secondary vulnerability risk is remarkably reduced; and the full-process automatic verification and DevOps integration module performs multi-dimensional security verification such as symbolic execution, fuzzy testing and the like on the generated repair code, and deeply integrates a development tool chain to realize real-time pushing and closed-loop management of a repair scheme.
Owner:BEIJING SHIXING TECH CO LTD

Cooperative scheduling method based on security agent

PendingCN120455151ABiological modelsSecuring communicationCoschedulingPrivate knowledge
The invention discloses a collaborative scheduling method based on a security agent, and relates to the technical field of network security design. The specific operation of the security agent collaborative scheduling method comprises the steps of system deployment and initialization, security operation task execution process, agent self-learning and capability evolution implementation, cross-domain security agent collaborative adaptation implementation and security operation visualization and traceability implementation. Connection paths between the security agent and business data, a private knowledge base, a security tool and multiple models are broken through, the problem that all elements in a traditional mode lack efficient communication and collaboration is solved, and by means of agent routing dynamic scheduling, A2A protocol interaction, MCP protocol tool calling, RAG business interface calling and multi-model combination, the security of the security agent is improved. Integration and intellectualization of the safety operation process are achieved, the continuity and the response speed of the operation process are improved, safety operation is more efficient and collaborative, and complex and variable safety requirements are met.
Owner:SHANGHAI DIGITAL SECURITY TECH CO LTD

Cybersecurity threat detection and mitigation classification system

In some implementations, a cybersecurity threat detection and mitigation system is provided. The system refines an artificial intelligence (AI) model with a corpus of historical data that represents security events that occurred, queries that were submitted by security analysts in response to the security events, and actions that were performed for mitigating the security events. Telemetry data that corresponds to behavior and performance of a computer network is collected and provided to the AI model. Based on the telemetry data, the AI model predicts a potential security threat to the computer network and performs an assessment of risk to the computer network. When the assessment of risk to the computer network indicates that the potential security threat is an actual security threat, a security alert that corresponds to the actual security threat is triggered. Other embodiments are described and claimed.
Owner:ARCTIC WOLF NETWORKS INC

Cloud-side collaborative multi-source data fusion security management and control system for intelligent power distribution equipment

The invention discloses a cloud edge collaborative multi-source data fusion safety management and control system for intelligent power distribution equipment, relates to the technical field of intelligent power grids and power distribution automation, and is used for managing and controlling 10-35 kV power distribution equipment. The system comprises an edge data acquisition module, a preprocessing module, a cloud storage management module, a cloud edge collaborative scheduling module, a multi-source data fusion module, an intelligent risk assessment module, a safety control execution module, a safety protection module and a man-machine interaction module. The modules are interacted through a 5G / industrial Ethernet; the acquisition module obtains multiple parameters, the preprocessing module cleans standardized data, the cloud side performs hierarchical storage, the scheduling module allocates tasks, the fusion module integrates data, the evaluation module performs grading risk, the protection module guarantees safety, and the interaction module performs visual alarm. The method improves the power distribution data quality and risk assessment precision, optimizes the cloud edge cooperation efficiency, enhances the safety protection capability, achieves the preventive operation and maintenance of equipment, reduces the fault and power failure time, reduces the operation and maintenance cost, and provides support for the safe and efficient operation of a power distribution network.
Owner:ZHUHAI GUOCHUANG INTERNET OF THINGS TECH CO LTD

Vehicle-mounted ad hoc network security communication system and method based on NTRU lattice cryptosystem

The invention belongs to the technical field of digital information transmission, and relates to a vehicle-mounted ad hoc network security communication system and method based on an NTRU lattice cryptosystem, and the system comprises a message signature module, a message encryption module, a message decryption module, an identity authentication module, and a key exchange module. The message signature module carries out signature by utilizing a private key and a random polynomial dynamically generated by a pseudo-random number generator based on an NTRU lattice cryptosystem; the message encryption module encrypts a to-be-sent message by randomly selecting a temporary polynomial and combining a public key of a receiver; the message decryption module is used for decrypting the received ciphertext # imgabs1 # by using a private key and an inverse element # imgabs0 # of a module p of the private key; the identity authentication module is used for performing identity authentication; the key exchange module realizes secure key exchange between communication nodes in the vehicle-mounted ad hoc network through an improved Blom key distribution protocol. The system improves the security and communication efficiency of the vehicle-mounted network.
Owner:CHANGCHUN UNIV OF TECH

Communication network security situation prediction method and system based on big data

The invention relates to the technical field of digital information transmission, and provides a communication network security situation prediction method and system based on big data, which break through the limitation of single data in the aspect of data fusion, integrate four large classes and 12 subclasses of multi-source heterogeneous data, and combine a dynamic weighting mechanism to make feature extraction more comprehensive and accurate; on the aspect of model architecture, CNN-Bi-LSTM-Attention three-level fusion and PSO optimization are adopted, spatial and temporal features are effectively captured, the convergence speed is increased, the prediction accuracy is high, and the false alarm rate is low; in the risk assessment aspect, a layered assessment system is constructed, and early warning is realized in combination with a dynamic threshold value and Monte Carlo simulation; the model training module innovatively adopts a federated learning mode, and the model generalization ability is improved while data privacy is guaranteed; the prediction analysis module deploys an optimization hybrid model, supports high-concurrency prediction and is short in response time; the visual decision-making module provides three-dimensional visualization and geographical drilling functions, and output data can be seamlessly connected with a third-party platform.
Owner:XINJIANG RUISHU YUNDING INFORMATION TECH CO LTD

Network security risk early warning method and system based on multi-source data fusion

The invention provides a network security risk early warning method and system based on multi-source data fusion, and relates to the technical field of network security, and the method comprises the steps: collecting multi-source security data; performing entity identification and association processing on the multi-source security data to obtain entity association information; performing space-time alignment fusion processing on the entity association information, and constructing a threat fusion matrix; performing risk analysis and threat identification on the threat fusion matrix based on rule engine matching, a behavior anomaly detection AI model and a graph neural network; and performing graded early warning based on a risk analysis and threat identification result. According to the network security risk early warning method and system based on multi-source data fusion, the accuracy and the real-time performance of network security risk early warning are remarkably improved through multi-source data fusion and multi-dimensional analysis.
Owner:GUANGZHOU JIAYANG INFORMATION TECHNOLOGY CO LTD