Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

20 results about "Network security management" patented technology

Network security management includes various rules and procedures adopted by network administrators to ensure that unauthorized users do not obtain access. Security involves a host of policies that limit access. The process makes the network secure and protects and manages network operations.

Dynamic security protection method and system based on behavior workflow and kalman filter

The application discloses a dynamic security protection method and system based on behavior workflow and Kalman filtering, and relates to the technical field of network security management and control.The application comprises the following steps: collecting multi-source heterogeneous original logs and performing standardized processing to obtain a standardized event stream; mapping the standardized event stream into an attack stage sequence, constructing and incrementally updating an attack semantic graph, and extracting attack progress observation values; establishing a state space model including attack progress and attack speed based on Kalman filtering, performing attack state estimation and trend prediction, and obtaining attack progress estimation and attack speed estimation; calculating threat urgency, and adjusting a two-way mandatory access control strategy based on the threat urgency classification. A dynamic security protection system capable of realizing real-time perception of attack process evolution, dynamic adjustment of access control strategy, high interpretability and strong adaptability is constructed, and deep coupling of attack semantic understanding, attack state estimation and access control strategy adjustment at the system level is realized.
Owner:SHENZHEN Y& D ELECTRONICS CO LTD

Computing power network security management and control method and device, computer device and storage medium

This invention belongs to the field of computing power networks and network security, and relates to methods, devices, computer equipment, and storage media for computing power network security management and control. The method includes: dividing computing power nodes into multiple logical regions, deploying a supervisory agent in each region, and deploying a coordinating agent at the core node to construct a hierarchical collaborative management and control architecture; collecting node behavior data and calculating a comprehensive trust value; issuing verification tasks and observing responses, and updating the posterior probability of the node's true security type; making a clear judgment on the node's final trust state based on the dominant probability principle; forming a unified security view of the entire network through real-time broadcasting and periodic reporting to the coordinating agent; and having the supervisory agent execute specific management and control strategies, providing feedback on the network status and adjusted parameters after execution. It features decentralization and high availability, enabling proactive verification and accurate identification, cross-domain collaboration and joint prevention and control, and adaptive dynamic defense.
Owner:SHENZHEN Y& D ELECTRONICS CO LTD

Network security management method and device, computer device and storage medium

The application belongs to the technical field of information security, and relates to a network security management method and device, computer equipment and a storage medium, the method comprising: setting network environment anomaly rules; obtaining network traffic data; pre-processing the network traffic data according to the network traffic data; extracting features from the pre-processed network traffic data to obtain network traffic data features; training a deep learning model according to the network traffic data features to identify abnormal traffic patterns; and real-time detecting network traffic according to the network environment anomaly rules, and automatically triggering a network security protection mechanism when network environment anomalies are detected. Real-time detection of network traffic and automatic triggering of the protection mechanism according to preset rules enable immediate response when threats first appear, greatly reducing potential losses; comprehensive monitoring and intelligent protection of the network environment improve the prevention, discovery and disposal capabilities of network security events, and provide a solid guarantee for the network security operation of enterprises.
Owner:SHENZHEN EWARE INFORMATION TECH CO LTD

AI-based multi-dimensional network attack tracing and early warning system

ActiveCN121585467BPathPingAlgorithm
The application relates to the technical field of network security, in particular to an AI-based multi-dimensional network attack tracing and early warning system, which comprises a network security management center, a multi-source data acquisition module, an AI multi-dimensional analysis module, a defense matching module and an early warning operation module, the AI multi-dimensional analysis module comprises an attack identification submodule, a path restoration submodule and a source positioning submodule; the application collects multi-source data through fusion, avoids feature missing caused by single data dimension, reduces the missing judgment probability, simultaneously adopts a fusion model to identify attack types and intensity, improves attack identification accuracy, constructs an attack propagation graph and accurately locates an attack source, solves the problems of low efficiency and poor accuracy of traditional tracing, simultaneously generates a graded early warning based on a risk level, ensures that attacks of different severity levels are responded to correspondingly, realizes automatic matching of defense strategies, avoids protection delay, and improves the active defense capability of network security.
Owner:GUANGZHOU SIYUN DATA TECH CO LTD

Terminal network security transmission method and platform for switch

The application provides a terminal network security transmission method and platform for an exchange, relates to the technical field of security transmission, and comprises the following steps: for a target exchange, a double-mapping module is constructed, and a screening encapsulation layer is configured at the first module end; source address information is received, security check screening and storage are performed, and safe address information is determined; a software-defined network is introduced, a physical communication network is divided and logically programmed, and a logical management network is determined; a forwarding storm evaluation based on a first time node is performed, and a storm evaluation result is determined; if the storm probability meets a probability threshold value, a storm control mechanism is triggered to perform flow control, and a flow control strategy is determined; and terminal network security transmission management is performed. The application solves the technical problem that the conventional network security management method usually relies on fixed rules and static security strategies, is difficult to adjust and respond to a dynamically changing network environment in time, and results in poor security in the data transmission process.
Owner:QIDONG SHUJIE SOFTWARE ENGINEERING CO LTD

A method and system for network security situation awareness based on honeycomb drive

ActiveCN122027363BPathPingPropagation delay
The application provides a network security situation awareness method and system driven by a honeynet, and relates to the technical field of network security management.The method provided by the application comprises the following steps: receiving threat event reporting from a honeynet trapping node, extracting an attacker behavior path, session content and triggering features, and performing first attack path correction according to the node's own topology position and attack flow information; when there are multiple honeynet trapping nodes simultaneously capturing events from the same attack source, the propagation delay and path deviation of the attack chain in the network are calculated through time synchronization and event matching between the honeynet trapping nodes, the attack situation is adjusted in real time, and the projection error of the attack propagation path in the network topology is corrected. The perception system realizes the collaborative work of distributed trapping nodes by introducing a honeynet driving mechanism, calculates the propagation delay and path deviation of the attack chain through time synchronization and event matching, and greatly improves the spatial accuracy of threat positioning.
Owner:INFORMATION & COMMNUNICATION BRANCH STATE GRID JIANGXI ELECTRIC POWER CO +1

Safety management system, method and electronic device for energy storage power station network

PendingCN122119993ASecuring communicationKnowledge based modelsSafety management systemsAttack
The application provides a kind of energy storage power station network security management system, method and electronic equipment, it is related to electric power system network security technical field, the system at least includes: perception layer, network layer, platform layer and response module;Wherein, perception layer is used to collect the original monitoring data of multiple types of terminal equipment;Network layer is used to encrypt original monitoring data, generates target monitoring data;Platform layer is used to carry out behavior detection to target monitoring data according to pre-trained intrusion detection model, and obtains behavior detection result;Wherein, behavior detection result includes: attack type and / or risk level of attack behavior;Response module is used to determine and execute corresponding target response strategy from pre-set response strategy library according to attack type and / or risk level.The application can improve the automation, precision and efficiency of energy storage power station network security protection.
Owner:HUANENG POWER INT INC HEBEI CLEAN ENERGY BRANCH +2

Network-based security management and control method and system for different scenarios

The application discloses a network security management and control method and system based on different scenes, and the method comprises the following steps: when the number of elements in a to-be-responded queue is less than a preset number, performing SQL injection detection on each request parameter based on a first interception rule to obtain an SQL injection detection result; when the number of elements in the to-be-responded queue reaches the preset number, simultaneously performing SQL injection detection on each request parameter based on a second interception rule to obtain an SQL injection detection result; and based on the SQL injection detection result obtained based on the first interception rule or the second interception rule and the request parameter to be responded, performing a corresponding response operation. The application can provide corresponding SQL injection detection schemes for different scenes, and can accelerate the response speed of a large number of SQL access requests in a short time.
Owner:OPEN ATOM OPEN SOURCE FOUNDATION

An identity recognition and access control method, system, device and storage medium

This application discloses a method, system, device, and storage medium for identity recognition and access control, relating to the field of network information security technology. The method includes: before a user terminal accesses a target network, receiving physical credentials or biometric information submitted by the user through a non-IP execution unit; performing identity authentication based on the physical credentials or biometric information, and binding the authentication result to a pre-configured user identity identifier; dynamically obtaining a minimum network access permission policy matching the user's responsibilities from a policy management platform according to the user identity identifier; and having the non-IP execution unit enforce proxy forwarding and protocol-level filtering on the user terminal's data communication according to the minimum access permission policy, ensuring all network interactions are completed through a controlled channel without assigning IP addresses. This application effectively solves the security risks caused by uncontrolled terminal access and meets the needs of refined network security management.
Owner:SYM TECH (GUANGDONG) CO LTD

Electronic device networking processing method and electronic device

The application discloses a processing method for electronic device networking and an electronic device. The method comprises the following steps: in the case that a docking station is connected to the electronic device, acquiring a first network address and first identification information stored in the docking station; determining, by a first controller in the electronic device, whether the first network address and the first identification information both meet a first condition; in the case that the first network address and the first identification information both meet the first condition, allowing the first controller to connect to a network and control the electronic device to enter an operating system; based on a first program installed in the operating system, respectively determining whether the first network address and the first identification information both meet a second condition; in the case that the first network address and the first identification information both meet the second condition, allowing the docking station to connect to the network based on the operating system. The method can accurately determine the identity of the electronic device and the docking station, and ensure the network security while facilitating the network security management.
Owner:联想开天科技有限公司

A centralized network security management and control system for local area networks

ActiveCN120768606BData acquisitionEngineering
This invention relates to a centralized network security management and control system for local area networks (LANs), belonging to the field of network security. The centralized management and control system of this invention includes: a data acquisition layer, a data storage layer, a data analysis layer, a management and control action layer, and a data presentation layer. The data acquisition layer uses Flume to collect log data and utilizes the RestService of the centralized management and control system to receive data pushed by external applications. The data storage layer uses MySQL and Elasticsearch for data persistence. The data analysis layer uses Flink as its core to implement correlation analysis functions, and performs multi-dimensional analysis of the collected real-time log data based on a rule engine to assess the network security situation. The management and control action layer issues action commands to the mobile terminal management system and the unified authentication management system through a specific HTTP interface. The data presentation layer displays the data to the user in a graphical format. This invention achieves proactive protection of the prototype system through unified management of the security situation within the LAN and timely response and handling of security risks.
Owner:BEIJING INST OF COMP TECH & APPL

A covert asset discovery method and system based on traffic monitoring and luring

ActiveCN122120006BInternet trafficNetwork security management
The application belongs to the technical field of network security management, and discloses a hidden asset discovery method and system based on traffic monitoring and decoy, which first monitors target network traffic to establish a communication behavior side file of each network entity, so as to depict the historical communication habits thereof; then, based on the file and pre-stored Internet mapping data, the hidden assets are screened, and decoy instructions are generated to guide the detection node to send decoy detection messages in the communication mode familiar to the assets; finally, the asset survival state is updated according to the decoy feedback. The method can significantly improve the comprehensive coverage and accurate identification capability of asset discovery, greatly reduce the false negative risk, effectively detect long-term inactive or silent configuration devices, eliminate the security blind area, and automatically distinguish normal changes and potential threats through data intercommunication, realize timely risk response, and meet the network security management requirements.
Owner:XI AN JIAOTONG UNIV

Security defense decision system and method applied to computer network

PendingCN122339833APathPingArea network
This invention relates to the field of network security management technology, and in particular to a security defense decision-making system and method applied to computer networks. It performs full-coverage monitoring of all nodes within a target network area, constructs a unified security information dataset, and uses multi-dimensional weighted calculations based on traffic anomalies, access record anomalies, and vulnerability risk levels. Combined with node topology importance, it achieves dual quantitative classification of single-node and regional network risks. Using a digital twin model, it can quickly locate high-risk nodes and weak links, directly pinpointing the risk factors with the highest scores. It also senses attack trends and automatically generates primary and secondary attack paths. Simultaneously, it selects optimal interception points based on a priority list of intersection points and path interception filtering methods, outputs a defense deployment list, and establishes a closed-loop mechanism for interception execution, effect evaluation, and secondary defense. When ineffective, the strategy is automatically iterated, and multiple ineffective attempts trigger manual warnings, improving the efficiency and effectiveness of security protection in the network environment.
Owner:广西农业职业技术大学 +1

A network security management method, device, equipment and machine readable storage medium

ActiveCN116318903BAttackIntrusion prevention system
This disclosure provides a network security management method, apparatus, device, and machine-readable storage medium. The method includes: obtaining attack signature IDs of attack features identified as false alarms based on an enabled false alarm prevention function; adding the attack signature IDs identified as false alarms to a false alarm prevention hash table; obtaining each attack signature ID associated with each attack behavior reported by the detection engine; matching the obtained attack signature IDs in the false alarm prevention hash table; and determining that the attack behavior associated with the successfully matched attack signature ID is a false alarm. Through the technical solution of this disclosure, for intrusion prevention systems that cannot promptly change or configure the signature database, a whitelist is established based on the attack signature IDs associated with attack behaviors determined to be false alarms. Subsequently, when an attack behavior associated with the same attack signature ID is detected again, it is directly considered a false alarm and the relevant packets are allowed to pass, thereby reducing the false alarm rate.
Owner:NEW H3C SECURITY TECH CO LTD

Jurisdictional enterprise network security management and control method and system and computer readable storage medium

The present application relates to a kind of jurisdiction enterprise network security management and control method, system and computer readable storage medium, the multi-source heterogeneous network security data of each enterprise in jurisdiction is collected, and the enterprise correlation graph is constructed;Using graph neural network constructs and learns enterprise correlation graph, obtains the graph embedding vector of each enterprise;In the attention calculation of graph neural network, the real-time risk score of neighbor enterprise is as input;Using large language model, the semantic analysis of unstructured text data is carried out, the implicit correlation between enterprises and potential risk semantics are mined, and the enterprise correlation graph is updated based on implicit correlation and potential risk semantics;Based on the updated enterprise correlation graph, graph embedding vector and real-time security data, the dynamic risk score of each enterprise is calculated using fusion risk score model;Based on dynamic risk score, risk trend is predicted, and using explainable technology, early warning information containing risk cause explanation is generated.The present application significantly improves the network security protection capability of jurisdiction.
Owner:ZHEJIANG PONSHINE INFORMATION TECH CO LTD

A big data-based network security intelligent management method and system

PendingCN122457361AAttackIntelligent management
The application discloses a kind of network security intelligent management method and system based on big data, it is related to network security management technical field.The network security intelligent management method based on big data, by collecting the encryption session data and terminal process data of each network element entity in network, by space-time fault tolerance association, extract encryption behavior feature vector;Collect historical behavior feature vector set, construct encryption communication behavior baseline, and by baseline abnormal risk assessment processing, give the entity risk label of each network element entity, and construct behavior risk association graph;It is input into the attack probability wave conduction model established in advance, by attack probability wave conduction and correction, output includes confidence rating and responsibility attribution attack event set, the application is by attack event set, to network is carried out security management, to enhance the identification detail of abnormal behavior under encryption scene, and let risk determination result be more close to network actual operating state, improve management precision and overall efficiency.
Owner:ANHUI MUCHEN TECHNOLOGY CO LTD

A Method and System for Multi-hop Path Analysis of Firewall Policies Based on Heterogeneous Graphs

PendingCN122093114AImprove traceabilityEfficient aggregationOther databases indexingSpecial data processing applicationsGraph spectraEngineering
This invention provides a method and system for multi-hop path analysis of firewall policies based on heterogeneous graphs, belonging to the field of network security management technology. The method includes: reading firewall policy data and network entity information; defining heterogeneous nodes and introducing virtual nodes based on a graph database; abstracting firewall policy rules into relational edges to obtain policy relational edges; and constructing a heterogeneous network access policy graph; obtaining query paths and traversing the heterogeneous network access policy graph to obtain multi-hop paths connecting the two ends of the query paths, thus obtaining a micro-path set; utilizing graph heterogeneity to analyze the micro-path set, obtaining shared policy relational edges; and identifying the same policy sequence in each multi-hop path to obtain a macro-policy path set. This invention solves the problems of inaccurate abstraction of heterogeneous models, difficulty in path tracing, redundant and overloaded analysis results, and low transmission efficiency of large-scale result sets in traditional policy analysis.
Owner:BEIJING UNIV OF POSTS & TELECOMM

System and method for enriching a generative model for cybersecurity incident management

PendingUS20260189607A1Incident management (ITSM)Data description
A system and method for enriching a generative model for managing a cybersecurity is presented. The method includes generating textual data from reasoning data of a reasoning model, wherein the reasoning model represents a probabilistic causal relationship amongst a plurality of nodes, and wherein the textual data describes an incident case of the reasoning model in relation to at least one cause; embedding the generated textual data at the generative model in order to create a semantic embedding space; and training the generative model with the embeddings of the textual data.
Owner:RADWARE LTD