Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

56 results about "Network security management" patented technology

Network security management includes various rules and procedures adopted by network administrators to ensure that unauthorized users do not obtain access. Security involves a host of policies that limit access. The process makes the network secure and protects and manages network operations.

Anomaly detection based on ensemble machine learning model

A security platform employs a variety techniques and mechanisms to detect security related anomalies and threats in a computer network environment. The security platform is “big data” driven and employs machine learning to perform security analytics. The security platform performs user / entity behavioral analytics (UEBA) to detect the security related anomalies and threats, regardless of whether such anomalies / threats were previously known. The security platform can include both real-time and batch paths / modes for detecting anomalies and threats. By visually presenting analytical results scored with risk ratings and supporting evidence, the security platform enables network security administrators to respond to a detected anomaly or threat, and to take action promptly.
Owner:CISCO TECHNOLOGY INC

Public multi-mode cloud network resource software security enhancement method based on neural symbol fusion reasoning

The invention relates to a public multi-mode cloud network resource software security enhancement method based on neural symbol fusion reasoning, which comprises the following steps: an intermediate representation generation stage: generating and optimizing an intermediate representation of a program through a fine-tuned large language model, and establishing semantic mapping from a source code to a structured logic representation; in the symbol language conversion stage, the intermediate representation generated by the large language model is converted into a domain-specific language fact set which can be recognized in the symbol logic reasoning stage, and formal and logic expression of program semantics is achieved; and a symbol logic reasoning stage: matching the fact set with the rule base through a symbol logic reasoning engine, performing detection and verification according to the safety rule, generating a structured report, and feeding back a result for optimization. The method is suitable for security enhancement of various core software systems in a public cloud network multi-modal network environment, high-precision security analysis is carried out on cross-modal and cross-subsystem fragmented codes in a compiling-free environment, and verifiable technical support is provided for public cloud network security control.
Owner:PEKING UNIV

Method and device for constructing network security management and control platform, electronic equipment and storage medium

The invention belongs to the field of network security, and relates to a method and device for constructing a network security management and control platform, electronic equipment and a storage medium, and the method comprises the steps: constructing a P-POT-PDRR security system model; constructing an intelligent multi-agent system consisting of a sensing agent, an analysis agent, an execution agent and a collaborative scheduling agent; through multi-source network data acquisition, cleaning, fusion and asset map construction, perception of a network environment is realized. Constructing an AI intelligent analysis and threat identification engine; based on an analysis result and a predefined strategy, risk assessment, attack path prediction and automatic response decision are realized, and the threat disposal time is shortened; and iterating parameters of the P-POT-PDRR security system model by continuously collecting execution feedback and optimizing strategy rules. The collaboration of a safety system is improved; the intelligent level is higher; the threat processing time is shortened, the loss caused by attacks is reduced, and the response efficiency is better; and the method has good expandability and compatibility.
Owner:SHENZHEN Y& D ELECTRONICS CO LTD

Data security storage method adaptive to network security prevention and control

The invention belongs to the technical field of network security management and control, and particularly relates to a data security storage method adaptive to network security prevention and control, which comprises the steps of data acquisition, multi-dimensional feature extraction, optimal prevention and control strategy generation, hierarchical encryption storage, abnormal behavior traceability and dynamic isolation response. According to the system, illegal data injection risks are blocked from an entrance through a source data authentication acquisition module, multi-dimensional effective features of data are extracted through a multi-dimensional feature purification module, the multi-dimensional effective features and real-time network threat situations are fused through a prevention and control strategy adaptation module, and an optimal prevention and control strategy is screened by quantifying the adaptation degree; the hierarchical encryption storage module reasonably distributes storage hierarchies and executes differential encryption and hierarchical backup, the abnormal behavior traceability module accurately identifies abnormal behaviors, and the dynamic isolation response module executes hierarchical isolation and triggers emergency response and strategy optimization, so that full-life-cycle safety management and control of data from collection, storage to access is realized, and the safety of data storage is improved. And the prevention and control accuracy and the system operation efficiency are both considered.
Owner:HENAN SHENGSHI TECH CO LTD

Network management authorization security management method and system for electric power communication network

The invention discloses a network management authorization security management method and system for an electric power communication network, and relates to the technical field of network security management. The method comprises the following steps: constructing a layered block chain network architecture; a user request is received, dynamic risk assessment is performed, a multi-factor identity authentication process is triggered, and after identity authentication is passed, an intelligent contract verifies the permission and generates a minimum permission access token; and the client accesses the token by means of the minimum authority, establishes an under-chain state channel, exchanges operation instructions and logs under the chain during the session, submits the aggregated hash values and the final states of all the operation logs to the slave block chains for evidence storage when the session is ended, and regularly anchors the state abstract of each slave block chain by the master block chain, so that the state abstract of each slave block chain is obtained. And completing global auditing traceability. The technical problem that in the prior art, network management operation authorization management of an electric power communication network lacks safety and traceability is solved, and the technical effects of improving the safety and credibility of network management operation authorization and achieving traceability of the whole operation process are achieved.
Owner:BENXI POWER SUPPLY COMPANY OF STATE GRID LIAONINGELECTRIC POWER SUPPLY

Wireless network security management method and system

The invention discloses a wireless network security management method and system. In the method, a system initialization module completes initialization, calls a key management module to generate signatures of a platform end and wireless equipment and encrypts asymmetric key pairs, and a wireless equipment management module records basic information of storage equipment. Before wireless equipment accesses, an authentication request containing first encryption information and first signature information is initiated through a request gateway module, after a platform end decrypts and verifies the signature to complete equipment authentication, second encryption information and second signature information are returned, and an equipment end decrypts and verifies the signature to complete bidirectional authentication. And network access is allowed in combination with the white list and the equipment registration state, and an administrator completes identity authentication and authority verification through the user authority management module and the request gateway module. After the equipment accesses the network, heartbeat communication and bidirectional authentication are carried out at regular intervals, equipment communication is controlled through a network communication strategy, and operation monitoring, situation analysis and log auditing are synchronously carried out. According to the invention, the problems of high access and operation and maintenance management security risk and the like in the prior art are solved.
Owner:JIANGSU NEW QUALITY INFORMATION TECH CO LTD +1

Dynamic detection method and device for network assets

ActiveCN121547379ATransmissionOpen portEngineering
The invention discloses a dynamic detection method and device for network assets, and belongs to the technical field of network security management. The method comprises the steps of performing initialization analysis and environment matching processing on a detection instruction received by a system, and determining a task scanning object of a to-be-scanned asset; performing first dynamic detection on assets to be scanned according to the task scanning object to obtain port opening information of all survival assets; performing second dynamic identification on all survival assets according to the task scanning object and the port open information to obtain structured data of an open port; and performing fusion correction on the structured data according to a preset fingerprint database, and establishing a complete asset model of the to-be-scanned asset according to a correction result. According to the invention, the detection efficiency of network assets can be improved and complete detection information can be obtained.
Owner:BEIJING CHANGYANG TECH CO LTD

A data management system and method applied to network security supervision

PendingCN122513138AData packData integrity
This invention discloses a data management system and method for network security supervision, relating to the field of network security management technology. It includes an evidence construction unit, a rule execution unit connected to the evidence construction unit, a dual-track evidence storage unit connected to both the evidence construction unit and the rule execution unit, and a display unit connected to the dual-track evidence storage unit. The invention deploys the evidence construction unit on network nodes, encapsulating evidence chain data packets based on 5-tuples and timestamps and calculating hash values ​​to ensure data integrity and traceability. The rule execution unit converts supervision regulations into executable code, calculates the results of evidence chain matching, and outputs the results. The dual-track evidence storage unit uploads the evidence hash values ​​to the blockchain via a first channel and the rule call records via a second channel, establishing a bidirectional cross-index to achieve dual evidence and behavior storage. The display unit retrieves data based on the cross-index for verification and visualizes the entire process, thus solving the problems of easily tampered evidence, opaque processes, and difficult-to-trace results.
Owner:GUANGDONG POWER GRID CO LTD +1

Comprehensive safety index evaluation method based on multi-task learning

PendingCN121567423ASecuring communicationSecurity metricData set
The invention provides a comprehensive security index evaluation method based on multi-task learning, and belongs to the technical field of network security management, and the method comprises the steps: synchronously collecting original data from a plurality of heterogeneous security data sources; a multi-task learning neural network model is constructed, and the model comprises a shared feature coding network for outputting shared features; the at least two heterogeneous task decoding networks are used for respectively mapping the shared features into preliminary security assessment results with different attributes; the fusion network is used for carrying out weighted fusion on the preliminary security assessment result to generate a comprehensive security index; using the multi-source security data set to train the multi-task learning neural network model; and inputting real-time security data of a to-be-evaluated system into the trained model, and outputting a comprehensive security index. The method has the advantages that the shared feature coding network can extract high-level feature representations with commonality from different data sources, and feature engineering dependence for a single data source or a single task is avoided.
Owner:LUOHE POWER SUPPLY OF HENAN ELECTRIC POWER CORP

Low-delay network security situation awareness system based on artificial intelligence

The invention discloses a low-delay network security situation awareness system based on artificial intelligence, which relates to the technical field of Internet of Things security and comprises a dynamic awareness topology reconstruction module, an edge gateway module, a terminal security agent module, a situation assessment and anomaly recognition engine module, a cross-domain linkage engine module and a situation early warning and visualization module. According to the method, a dynamic network security management closed loop is constructed, a terminal state is collected by a topology reconstruction module, a sensing cluster is established and topology is reconstructed, an edge gateway summarizes equipment operation data, a situation assessment and anomaly recognition engine analyzes and recognizes network anomaly and an attack link through model fusion, and a cross-domain linkage engine generates a protection instruction. And the terminal security agent executes operation, and the situation early warning and visualization module realizes global display and graded early warning, so that the problems of poor static topology adaptability, high data transmission delay and disjunction of situation assessment and protection response in the prior art are solved, and reliable security guarantee is provided for the dynamic network of the Internet of Things.
Owner:GUANGZHOU SIYUN DATA TECH CO LTD

Dynamic security protection method and system based on behavior workflow and kalman filter

The application discloses a dynamic security protection method and system based on behavior workflow and Kalman filtering, and relates to the technical field of network security management and control.The application comprises the following steps: collecting multi-source heterogeneous original logs and performing standardized processing to obtain a standardized event stream; mapping the standardized event stream into an attack stage sequence, constructing and incrementally updating an attack semantic graph, and extracting attack progress observation values; establishing a state space model including attack progress and attack speed based on Kalman filtering, performing attack state estimation and trend prediction, and obtaining attack progress estimation and attack speed estimation; calculating threat urgency, and adjusting a two-way mandatory access control strategy based on the threat urgency classification. A dynamic security protection system capable of realizing real-time perception of attack process evolution, dynamic adjustment of access control strategy, high interpretability and strong adaptability is constructed, and deep coupling of attack semantic understanding, attack state estimation and access control strategy adjustment at the system level is realized.
Owner:SHENZHEN Y& D ELECTRONICS CO LTD

Artificial intelligence-based collaborative office network security management method and system and medium

The application discloses a collaborative office network security management method and system based on artificial intelligence and a medium, belongs to the technical field of artificial intelligence network security, and is used for solving the technical problem that when the existing collaborative office network has network abnormal conditions or network security events, the emergency mechanism mainly depends on manual intervention, and the response efficiency is low when data leakage or system paralysis is caused. The method comprises the following steps: through an edge computing node and based on an artificial intelligence engine architecture, performing edge preprocessing on initial office network data about adversarial samples to obtain a network feature matrix based on the initial office network data; through the artificial intelligence engine architecture, performing double-channel network anomaly detection processing on the network feature matrix to obtain network anomaly detection result data; and according to the network anomaly detection result data, performing corresponding network risk response actions and automatically generating a network anomaly solution strategy.
Owner:山东大通世纪实业有限公司

Multi-dimensional network attack tracing and early warning system based on AI

The invention relates to the technical field of network security, in particular to an AI-based multi-dimensional network attack tracing and early warning system, which comprises a network security management center, a multi-source data acquisition module, an AI multi-dimensional analysis module, a defense matching module and an early warning operation module, the AI multi-dimensional analysis module comprises an attack identification sub-module, a path return sub-module and a source positioning sub-module; according to the method, through multi-source data fusion collection, feature missing caused by a single data dimension is avoided so as to reduce the missed judgment probability, meanwhile, the fusion model is adopted to recognize the attack type and intensity, the attack recognition accuracy is improved, the attack propagation graph is constructed, the attack source is accurately positioned, and the problems of low efficiency and poor accuracy of traditional tracing are solved; and meanwhile, graded early warning is generated based on risk grades, so that attacks with different severity degrees are enabled to obtain corresponding responses, automatic matching of defense strategies is realized, protection delay is avoided, and the active defense capability of network security is improved.
Owner:GUANGZHOU SIYUN DATA TECH CO LTD

Computing power network security management and control method and device, computer device and storage medium

This invention belongs to the field of computing power networks and network security, and relates to methods, devices, computer equipment, and storage media for computing power network security management and control. The method includes: dividing computing power nodes into multiple logical regions, deploying a supervisory agent in each region, and deploying a coordinating agent at the core node to construct a hierarchical collaborative management and control architecture; collecting node behavior data and calculating a comprehensive trust value; issuing verification tasks and observing responses, and updating the posterior probability of the node's true security type; making a clear judgment on the node's final trust state based on the dominant probability principle; forming a unified security view of the entire network through real-time broadcasting and periodic reporting to the coordinating agent; and having the supervisory agent execute specific management and control strategies, providing feedback on the network status and adjusted parameters after execution. It features decentralization and high availability, enabling proactive verification and accurate identification, cross-domain collaboration and joint prevention and control, and adaptive dynamic defense.
Owner:SHENZHEN Y& D ELECTRONICS CO LTD

Network security management method and device, computer device and storage medium

The application belongs to the technical field of information security, and relates to a network security management method and device, computer equipment and a storage medium, the method comprising: setting network environment anomaly rules; obtaining network traffic data; pre-processing the network traffic data according to the network traffic data; extracting features from the pre-processed network traffic data to obtain network traffic data features; training a deep learning model according to the network traffic data features to identify abnormal traffic patterns; and real-time detecting network traffic according to the network environment anomaly rules, and automatically triggering a network security protection mechanism when network environment anomalies are detected. Real-time detection of network traffic and automatic triggering of the protection mechanism according to preset rules enable immediate response when threats first appear, greatly reducing potential losses; comprehensive monitoring and intelligent protection of the network environment improve the prevention, discovery and disposal capabilities of network security events, and provide a solid guarantee for the network security operation of enterprises.
Owner:SHENZHEN EWARE INFORMATION TECH CO LTD

AI-based multi-dimensional network attack tracing and early warning system

ActiveCN121585467BPathPingAlgorithm
The application relates to the technical field of network security, in particular to an AI-based multi-dimensional network attack tracing and early warning system, which comprises a network security management center, a multi-source data acquisition module, an AI multi-dimensional analysis module, a defense matching module and an early warning operation module, the AI multi-dimensional analysis module comprises an attack identification submodule, a path restoration submodule and a source positioning submodule; the application collects multi-source data through fusion, avoids feature missing caused by single data dimension, reduces the missing judgment probability, simultaneously adopts a fusion model to identify attack types and intensity, improves attack identification accuracy, constructs an attack propagation graph and accurately locates an attack source, solves the problems of low efficiency and poor accuracy of traditional tracing, simultaneously generates a graded early warning based on a risk level, ensures that attacks of different severity levels are responded to correspondingly, realizes automatic matching of defense strategies, avoids protection delay, and improves the active defense capability of network security.
Owner:GUANGZHOU SIYUN DATA TECH CO LTD

Network security management platform

The utility model discloses a network security management platform, which belongs to the field of network security and comprises a plurality of switches for transmitting network data and a data cabinet for storing the switches in batches, the data cabinet comprises a cabinet body and a plurality of L-shaped fixing plates penetrating through the side wall of the cabinet body, and the switches are positioned in grooves of the L-shaped fixing plates. Compared with the prior art, the device has the advantages that the wiring port stretching assembly is installed between the switch and the rear baffle of the L-shaped fixing plate, free stretching of the length of an optical fiber is completed through the optical fiber coil socket, and in order to prevent the optical fiber from being damaged due to rotation, the optical fiber rotary connector is installed on an input main line of the optical fiber; therefore, the insertion end of the optical fiber wire coil socket can rotate freely under the condition that the signal is not influenced.
Owner:BEIJING SHIJIHUAFENG SCI TECH DEV CO LTD

Network adaptive management system based on dynamic network security

The application belongs to the field of network security management, relates to data analysis technology, and is used for solving the problem that the prior art cannot linearly track from the perspective of an operation user and overall risk assessment of short-term behavior of the same network user, and particularly relates to a network adaptive management system based on dynamic network security, which comprises a behavior monitoring module, a security analysis module and a risk analysis module connected in sequence in communication, and the behavior monitoring module, the security analysis module and the risk analysis module are all connected in communication with a database; the application can finely and weightedly quantitatively evaluate the security of each combination element; the evaluation method fully considers the differentiated influence of different security attributes such as permission, privacy and network fluctuation on the security of network behavior, so that the finally calculated security coefficient of the combination element is more representative and accurate.
Owner:GUANGZHOU SIYUN DATA TECH CO LTD

Power monitoring network security server (SPC-8271F-03)

1. The name of the design product: power monitoring network security server (SPC-8271F-03). 2. The use of the design product: to collect and monitor the network security information of power, upload events to the network security management platform and provide service agent functions. 3. The design points of the design product: in shape. 4. The picture or photo that best indicates the design points: perspective view 1.
Owner:EVOC SMART IOT TECH CO LTD

Unified security data management system based on data lake

The invention belongs to the field of data management, and provides a unified security data management system based on a data lake, and the system comprises a data collection subsystem which is used for collecting multi-source security data in a key region; the data lake storage subsystem is used for storing the multi-source security data by adopting a distributed data lake architecture and performing full-period management on the stored multi-source security data; and the data service subsystem is used for extracting security abnormal data in the multi-source security data, mining associated information among different security events in the security abnormal data through an association rule algorithm, and inputting the security abnormal data and the associated information into a pre-established trend prediction model to obtain a future security trend prediction result. According to the scheme provided by the invention, flexible storage of multiple types of data is realized and the resource cost is reduced by virtue of the data lake storage subsystem, and effective conversion from passive response to active pre-judgment defense is realized by virtue of the data service subsystem, so that the whole network security management and control capability is remarkably improved.
Owner:HUANENG INFORMATION TECH CO LTD

Mobile hotspot detection method based on multi-dimensional traffic characteristics and machine learning

The invention discloses a mobile hotspot behavior detection method based on multi-dimensional flow characteristics and machine learning, and the method comprises the steps: monitoring a network outbound IP message flow in a preset time window; extracting a multi-dimensional feature set including TTL statistical features, TTL dynamic association features and IP ID sequence features, and constructing a feature vector of the time window; and inputting the feature vector into a pre-trained and optimized random forest classifier for judgment, and determining whether the corresponding terminal equipment has a mobile hotspot behavior or not. According to the method, the statistical characteristic, the dynamic characteristic and the protocol underlying sequence characteristic of the flow are fused, so that a characteristic space with high discrimination capability is constructed, the strong dependence on network topology based on TTL absolute value comparison in the prior art is effectively overcome, and the problem of high false alarm rate caused by'statistical fuzziness' in a complex network scene is solved. According to the method and the device, the message sent by the terminal accessing the network through the hotspot can be accurately identified, and finer data is provided for network security management and control and service system evaluation.
Owner:SOUTHEAST UNIV

Local area network device network security early warning method based on zero trust architecture

The application discloses a local area network device network security early warning method based on a zero trust architecture, and relates to the technical field of network security.Through technical means such as access request interception and processing, dynamic identity authentication, terminal behavior analysis and device security index evaluation, real-time security monitoring and early warning of terminal devices in a local area network are realized; through a blocking module, access requests of the local area network are grouped and processed, and an access request sequence is constructed based on time, space and structural characteristics; then, a terminal device is subjected to multi-factor dynamic identity authentication by using a big data analysis module, and safe and reliable terminal devices are screened out in combination with device behavior baselines and matching degree calculation; next, the current device security index of the terminal device is evaluated by means of system logs and memory usage rate data in a backtracking period; finally, the access request is released or blocked according to a security index threshold, and corresponding early warning information is generated, thereby providing decision support for network security management.
Owner:SICHUAN PUBLIC SUPERVISION CONSULTING CO LTD

Automobile network security project process management method and system, electronic equipment and storage medium

The invention relates to an automobile network security project process management method and system, electronic equipment and a storage medium. The method comprises the following steps: monitoring the progress of a vehicle type project, and when it is detected that the progress of the vehicle type project reaches a target development valve point, creating a process of a network security activity; a deliverable generated by the network security activity is acquired and analyzed, and the analyzed deliverable is associated and matched with the corresponding regulation terms based on a preset regulation knowledge graph; monitoring project risk information generated in the execution process of the network security activity and the analysis process of the deliverable, determining a target part corresponding to the project risk information, and performing full-link traceability and risk disposal on the target part; verifying the compatibility between the safety tool and the test target of the test task; and acquiring multi-dimensional index data of the network security activity, and analyzing based on the multi-dimensional index data to obtain a network security management short board of the vehicle type project. By adopting the method, network security closed-loop management of the full life cycle of the vehicle type project can be formed.
Owner:CHONGQING SOKON IND GRP CO LTD

Network security management and control method and device, terminal equipment and storage medium

The invention discloses a network security management and control method and device, terminal equipment and a storage medium, and relates to the technical field of network security, and the method comprises the steps: obtaining a plurality of ports of a target power grid dispatching control center, and constructing a port topological graph according to the plurality of ports; constructing a risk identification network corresponding to each port, and determining a port risk value of each port according to the risk identification network; determining the port corresponding to the port risk value greater than or equal to the first risk threshold as a high-risk port, and isolating the high-risk port; and determining the port corresponding to the port risk value which is less than the first risk threshold and greater than or equal to the second risk threshold as an abnormal port, performing association verification and synchronous verification on the abnormal port based on the port topological graph, determining a threat port in the port topological graph, and isolating the threat port. According to the invention, related potential threat abnormal ports can be determined according to the abnormal ports and are isolated, so that the effect of network security management and control can be effectively improved.
Owner:POWER DISPATCHING CONTROL CENT OF GUANGDONG POWER GRID CO LTD

Terminal network security transmission method and platform for switch

The application provides a terminal network security transmission method and platform for an exchange, relates to the technical field of security transmission, and comprises the following steps: for a target exchange, a double-mapping module is constructed, and a screening encapsulation layer is configured at the first module end; source address information is received, security check screening and storage are performed, and safe address information is determined; a software-defined network is introduced, a physical communication network is divided and logically programmed, and a logical management network is determined; a forwarding storm evaluation based on a first time node is performed, and a storm evaluation result is determined; if the storm probability meets a probability threshold value, a storm control mechanism is triggered to perform flow control, and a flow control strategy is determined; and terminal network security transmission management is performed. The application solves the technical problem that the conventional network security management method usually relies on fixed rules and static security strategies, is difficult to adjust and respond to a dynamically changing network environment in time, and results in poor security in the data transmission process.
Owner:QIDONG SHUJIE SOFTWARE ENGINEERING CO LTD

A method and system for network security situation awareness based on honeycomb drive

ActiveCN122027363BPathPingPropagation delay
The application provides a network security situation awareness method and system driven by a honeynet, and relates to the technical field of network security management.The method provided by the application comprises the following steps: receiving threat event reporting from a honeynet trapping node, extracting an attacker behavior path, session content and triggering features, and performing first attack path correction according to the node's own topology position and attack flow information; when there are multiple honeynet trapping nodes simultaneously capturing events from the same attack source, the propagation delay and path deviation of the attack chain in the network are calculated through time synchronization and event matching between the honeynet trapping nodes, the attack situation is adjusted in real time, and the projection error of the attack propagation path in the network topology is corrected. The perception system realizes the collaborative work of distributed trapping nodes by introducing a honeynet driving mechanism, calculates the propagation delay and path deviation of the attack chain through time synchronization and event matching, and greatly improves the spatial accuracy of threat positioning.
Owner:INFORMATION & COMMNUNICATION BRANCH STATE GRID JIANGXI ELECTRIC POWER CO +1

Safety management system, method and electronic device for energy storage power station network

The application provides a kind of energy storage power station network security management system, method and electronic equipment, it is related to electric power system network security technical field, the system at least includes: perception layer, network layer, platform layer and response module;Wherein, perception layer is used to collect the original monitoring data of multiple types of terminal equipment;Network layer is used to encrypt original monitoring data, generates target monitoring data;Platform layer is used to carry out behavior detection to target monitoring data according to pre-trained intrusion detection model, and obtains behavior detection result;Wherein, behavior detection result includes: attack type and / or risk level of attack behavior;Response module is used to determine and execute corresponding target response strategy from pre-set response strategy library according to attack type and / or risk level.The application can improve the automation, precision and efficiency of energy storage power station network security protection.
Owner:HUANENG POWER INT INC HEBEI CLEAN ENERGY BRANCH +2

Vulnerability early warning system and method based on threat intelligence

The invention relates to the technical field of network security, and discloses a vulnerability early warning system and method based on threat intelligence, and the system comprises a data obtaining module which obtains a plurality of groups of threat intelligence data corresponding to network equipment based on all vulnerability detection time points, and determines a plurality of threat intelligence data sequences according to all the threat intelligence data; the threat determination module analyzes each threat intelligence data sequence and determines a vulnerability threat metric value of the network equipment; a threat calculation module performs multi-source splitting on all vulnerability threat metric values, and calculates a multi-source vulnerability threat coefficient of the network equipment; and the vulnerability early warning module judges whether to send vulnerability early warning to the network equipment according to the relationship between the multi-source vulnerability threat coefficient and a preset multi-source vulnerability threat coefficient, so that multi-source threat intelligence can be effectively integrated, accurate quantitative analysis of the network equipment is realized, the vulnerability early warning analysis precision and efficiency are ensured, the global security of the network space is controlled, and the security of the network equipment is improved. And security technical support is provided for network security management and control capability.
Owner:HUANENG INFORMATION TECH CO LTD

Satellite network encrypted traffic classification method and system based on cost penalty

The invention discloses a satellite network encrypted traffic classification method and system based on cost penalty, and the method comprises the steps: creating a dynamic cost penalty matrix according to the class sample distribution, and effectively relieving the class imbalance influence through quantifying the error classification cost; a multi-modal feature extraction layer (including 1D-CNN, Bi-LSTM and SAE models) is utilized to automatically learn space, time and statistical features from data packet level and session level original data, and limitation of artificial feature extraction is avoided; an improved cross entropy loss function is combined in a cost penalty layer, a weighting mechanism is introduced to carry out enhanced penalty on misclassification samples, and model output is optimized through prediction value adjustment and Softmax conversion. According to the method, the accuracy and robustness of encrypted traffic classification can be remarkably improved, the method is particularly suitable for a high-delay and dynamic topology satellite network environment, and effective technical support is provided for network security management.
Owner:北京物宇星联科技发展有限公司