Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

191 results about "Network security management" patented technology

Network security management includes various rules and procedures adopted by network administrators to ensure that unauthorized users do not obtain access. Security involves a host of policies that limit access. The process makes the network secure and protects and manages network operations.

System and method for monitoring and analyzing security event logs of power grid communication network in real time

The invention discloses a security event log real-time monitoring and analyzing system and method for a power grid communication network, and relates to the technical field of network security management. The causal relationship graph building module is used for building a causal relationship graph of the target power grid communication network; the multi-dimensional correlation analysis module is used for collecting and analyzing multi-source heterogeneous log data in real time; the abnormal security event identification module is used for identifying an abnormal security event according to the causal relationship graph and the multi-dimensional correlation analysis result; and the attack chain tracking response module is used for tracking the attack chain. According to the method, the technical problem that the existing power grid communication network security monitoring lacks tracking of abnormal event evolution from the time dimension and cannot accurately identify and track a multi-stage attack chain is solved, and the effects of dynamically tracking the evolution process of the abnormal event and identifying a potential attack chain by establishing a time causal chain graph are achieved. And the detection precision and the response speed of the attack behavior are improved.
Owner:HAINAN POWER GRID CO LTD

Network security intelligent management and control system based on big data

The invention discloses a network security intelligent management and control system based on big data, and relates to the field of network security management. Comprising a data acquisition processing module, an intelligence fusion analysis module, a threat dynamic detection module, an attack deduction prediction module, a virtual mapping simulation module, an edge collaborative defense module, a defense strategy optimization module, an automatic decision execution module and a threat intelligence sharing module. According to the method, the detection capability of complex network attacks is improved, the attack path in the network environment can be visually presented, the security operation and maintenance efficiency is improved, the attack path is accurately blocked, and the attack success rate is reduced; comprehensive security event priority ranking can be realized, the scientificity of defense decision is improved, meanwhile, the system can adapt to different attack scenes, the defense efficiency is improved, it is ensured that a defense strategy always adapts to the current security situation, resource waste is avoided, and the defense cost-benefit ratio is improved.
Owner:JINAN JUBANG INFORMATION TECHNOLOGY CO LTD

Power monitoring system distribution network security management active defense system

The invention relates to the technical field of network security management, in particular to an active defense system for power monitoring system distribution network security management. The safety monitoring unit is used for collecting and analyzing network data in real time; the intrusion detection unit is used for identifying suspicious activities and attack signs; the risk assessment unit further analyzes the suspicious activities and the attack signs and assesses the influence degree of the suspicious activities and the attack signs on the power grid security; and the decision support response unit provides coping strategy suggestions according to the result of the risk assessment and executes the provided countermeasures. By integrating the safety monitoring unit, the intrusion detection unit, the risk assessment unit and the decision support response unit, real-time collection, analysis and processing of network data are realized. Particularly, the intrusion detection unit adopts an advanced network flow behavior recognition model and a system log behavior recognition model, so that behaviors which are not consistent with a normal communication mode and abnormal operation records in a system log can be effectively recognized.
Owner:STATE GRID SHANDONG ELECTRIC POWER CO

Network security multi-mode intelligent detection system and method

The invention provides a network security multi-mode intelligent detection system and method, relates to the technical field of network security management, and is applied to a power distribution system which comprises a communication device and a power distribution device. The network security multi-modal intelligent detection system comprises a multi-modal data acquisition module used for acquiring network flow data, equipment characteristic data and behavior data of a power distribution system; the detection engine module is used for analyzing and detecting the network flow data, the equipment characteristic data and the behavior data to obtain a detection result; and the decision and response module is used for performing risk assessment according to the detection result based on a preset risk assessment model to obtain a risk grading result and a response strategy. According to the invention, comprehensive monitoring and deep analysis of the network security condition of the power distribution system are realized. By integrating multi-modal data, the limitation of a traditional single data detection mode is effectively overcome, and the accuracy and timeliness of threat detection are improved.
Owner:GUO WANG ZHE JIANG SHENG DIAN LI YOU XIAN GONG SI CI XI SHI GONG DIAN GONG SI

Network space map surveying and mapping method and system based on multi-source data fusion

The invention discloses a network space map surveying and mapping method and system based on multi-source data fusion, and the method comprises the steps: obtaining a multi-source data set in a unified format based on network flow data, equipment information data and geographic position data; obtaining a network asset entity and an incidence relation graph thereof through entity identification and correlation analysis based on the multi-source data set with the uniform format; obtaining a network space three-dimensional map model through three-dimensional space mapping and visual rendering based on the network asset entity and the association relationship map thereof; based on the network space three-dimensional map model, performing dynamic updating according to the accessed real-time data flow to obtain real-time network space situation data; and obtaining a network security risk assessment result through anomaly detection and threat identification based on the real-time network space situation data. According to the invention, visual display and security situation awareness of the network space are realized, and a brand new decision support tool is provided for network security management.
Owner:WEBRAY TECH BEIJING CO LTD

Network security management system based on big data

The invention relates to the technical field of network security management, in particular to a network security management system based on big data, which comprises a data acquisition and integration unit, a dynamic threshold setting unit, a fuzzy comprehensive evaluation unit, a machine learning optimization unit and a control unit. The acquisition process has intelligent characteristics and adopts a block chain to cache data, the dynamic threshold setting unit constructs a model to adjust a threshold by combining a hidden Markov model, kernel density estimation and a reinforcement learning algorithm for different network crime types, and the fuzzy comprehensive evaluation unit determines a membership function and distributes weights by applying a fuzzy mathematical algorithm. And the machine learning optimization unit uses historical data to train and update the model, assists in case-related account determination, effectively solves the problems of missed determination and misjudgment caused by a fixed threshold value in traditional account risk assessment, and improves the accuracy of network criminal account risk assessment.
Owner:CHENGDU DIGITAL STAR TECHNOLOGY CO LTD

Method, device and system for constructing attack graph, and storage medium

The embodiment of the invention provides a method, device and system for constructing an attack graph, and a storage medium, and relates to the technical field of network security. The method comprises the steps that based on a test case knowledge base of a target system, an attack graph information expansion algorithm is executed through a knowledge graph technology, and expanded information is obtained; utilizing the expanded information to construct an attribute attack graph of the target system; and carrying out attack path description on vulnerabilities of the target system based on the attribute attack graph. An attack graph information expansion algorithm is executed through a test case knowledge base based on a target system and by means of a knowledge graph technology, information needed for constructing an attack graph can be obtained, potential attack paths can be mined, the attack graph information is expanded, and then a comprehensive and accurate attribute attack graph is constructed. According to the method, effective description of the vulnerability attack path of the target system is realized, so that the constructed attack graph can reflect the security condition of the network system more truly, more scientific decision support is provided for network security management personnel, and the network security protection effect is improved.
Owner:STATE GRID SHANDONG ELECTRIC POWER CO +2

Anomaly detection based on ensemble machine learning model

A security platform employs a variety techniques and mechanisms to detect security related anomalies and threats in a computer network environment. The security platform is ā€œbig dataā€ driven and employs machine learning to perform security analytics. The security platform performs user / entity behavioral analytics (UEBA) to detect the security related anomalies and threats, regardless of whether such anomalies / threats were previously known. The security platform can include both real-time and batch paths / modes for detecting anomalies and threats. By visually presenting analytical results scored with risk ratings and supporting evidence, the security platform enables network security administrators to respond to a detected anomaly or threat, and to take action promptly.
Owner:CISCO TECHNOLOGY INC

Network security protection management system and method based on big data

The invention discloses a network security protection management system and method based on big data, and relates to the technical field of network security management, and the method comprises the steps: collecting industrial protocol layer data, physical sensor data and process parameters, extracting network behavior features, physical features and process correlation features, and constructing an industrial security feature vector; according to the security weight coefficient and the industrial security feature vector of the current process stage, calculating a threat score of the equipment, and dynamically adjusting a threat level through a three-level verification mechanism; constructing an equipment dependency graph, performing risk diffusion calculation based on the adjacent matrix and the attenuation coefficient, and generating a risk diffusion priority list to adjust an isolation strategy; an improved multi-target genetic algorithm is adopted to solve a Pareto optimal solution set, an equipment recovery sequence and a process parameter adjustment scheme are determined, and a recovery instruction is issued to realize safe recovery, so that the dynamic perception and accurate defense capability for industrial network threats is improved, and the safety and stability of industrial production are guaranteed.
Owner:JIANGXI YUSHAN EVERGREEN CEMENT CO LTD

Power data communication network security situation prediction method

The invention discloses a power data communication network security situation prediction method, which comprises the following steps of: aiming at a hot spot multi-dimensional orientation description vector, acquiring a network security event log, adopting a time sequence event chain construction technology, and determining event triggering frequency and service interruption duration related to a hot spot through matching of event triggering frequency and event association strength, so as to predict the security situation of the hot spot. Obtaining an event chain sequence; extracting an event trigger frequency, a service interruption duration and a hotspot influence range from the event chain sequence, and judging a hotspot life cycle stage through quantification of a node load state and traffic abnormal fluctuation to obtain a life cycle quantitative index; and extracting a hot spot influence range and traffic abnormal fluctuation from the global security situation view data, and if the hot spot influence range or the traffic abnormal fluctuation exceeds a preset threshold, adjusting weight redistribution through a node load state to obtain an incremental change feature set. According to the method, the hotspot situation in the power data communication network can be comprehensively and dynamically analyzed, and powerful support is provided for network security management and decision making.
Owner:SUQIAN POWER SUPPLY COMPANY OF JIANGSU PROVINCE POWER

Network security attack threat analysis method and device based on rough set

The invention provides a network security attack threat analysis method and device based on a rough set, and relates to the technical field of network security. The method comprises the following steps: collecting real-time network flow data, analyzing the characteristics of the network flow data by applying a data attribute evaluation technology in a rough set theory, evaluating the fluctuation intensity and the fluctuation amplitude of the data, dynamically adjusting the size of a time window, and obtaining a time window size adjustment parameter. According to the invention, abnormal data are quickly positioned through statistical characteristics, the efficiency and response speed of network security monitoring are improved, resources are dynamically configured by evaluating the abnormal frequency and severity in the data stream, and the frequency of network monitoring is optimized, so that the network security management is more active and prospective, and the network security management efficiency is improved. The response and processing capabilities of the network are detected by dynamically adjusting the attack frequency, the network security configuration is further optimized, and the overall security and stability of the network are greatly improved.
Owner:JINQICHUANG (BEIJING) TECH CO LTD

Public multi-mode cloud network resource software security enhancement method based on neural symbol fusion reasoning

The invention relates to a public multi-mode cloud network resource software security enhancement method based on neural symbol fusion reasoning, which comprises the following steps: an intermediate representation generation stage: generating and optimizing an intermediate representation of a program through a fine-tuned large language model, and establishing semantic mapping from a source code to a structured logic representation; in the symbol language conversion stage, the intermediate representation generated by the large language model is converted into a domain-specific language fact set which can be recognized in the symbol logic reasoning stage, and formal and logic expression of program semantics is achieved; and a symbol logic reasoning stage: matching the fact set with the rule base through a symbol logic reasoning engine, performing detection and verification according to the safety rule, generating a structured report, and feeding back a result for optimization. The method is suitable for security enhancement of various core software systems in a public cloud network multi-modal network environment, high-precision security analysis is carried out on cross-modal and cross-subsystem fragmented codes in a compiling-free environment, and verifiable technical support is provided for public cloud network security control.
Owner:PEKING UNIV

Network security situation awareness method and system

The invention relates to the technical field of network security monitoring, and discloses a network security situation awareness method and system, and the method comprises the steps: collecting a multi-source heterogeneous log, carrying out the standardized analysis, and obtaining log event data; performing real-time analysis by utilizing a dynamic baseline association engine based on the log event data to obtain log association alarm data, analyzing a triple from the log association alarm data, constructing a basic knowledge graph based on the triple, performing rule reasoning and embedded reasoning, and integrating reasoning results to form a situation-enhanced security situation knowledge graph; threat data are extracted according to the security situation knowledge graph, the threat data are optimized in combination with a graph neural network GAT to obtain a final network attack threat value, network security situation awareness is carried out based on the network attack threat value, and the threat data comprise comprehensive criticality and an attack influence range. According to the invention, the efficiency and effect of network security management can be improved.
Owner:TONGFANG KNOWLEDGE DIGITAL PUBLISHING TECH CO LTD

Network security management method and system based on big data model

The invention relates to the technical field of network security, and discloses a network security management method and system based on a big data model, and the method comprises the steps: 1, converting multi-source heterogeneous data into a graph node containing a device entity, an I P entity and a user entity, and an interaction edge containing a timestamp and a relation type; step 2, constructing an attack chain dynamic evolution equation based on graph nodes and interaction edges, wherein the equation comprises an attacker action parameter and a defender action parameter; and step 3, inputting a time fusion Transform model to obtain probability distribution of a future attack action sequence by using a state variable corresponding to the attack chain dynamic evolution equation. According to the method, the technical scheme of constructing an attack chain dynamic evolution equation based on a differential game model, predicting an attack action sequence through time fusion Transformer and dynamically updating a defense strategy through meta reinforcement learning is adopted, and the technical effects of accurately modeling an attack evolution path, predicting an attack behavior in advance and generating a self-adaptive defense strategy in real time are achieved.
Owner:BEIJING SUPER EXPLORATION TECH CO LTD

Method and device for constructing network security management and control platform, electronic equipment and storage medium

The invention belongs to the field of network security, and relates to a method and device for constructing a network security management and control platform, electronic equipment and a storage medium, and the method comprises the steps: constructing a P-POT-PDRR security system model; constructing an intelligent multi-agent system consisting of a sensing agent, an analysis agent, an execution agent and a collaborative scheduling agent; through multi-source network data acquisition, cleaning, fusion and asset map construction, perception of a network environment is realized. Constructing an AI intelligent analysis and threat identification engine; based on an analysis result and a predefined strategy, risk assessment, attack path prediction and automatic response decision are realized, and the threat disposal time is shortened; and iterating parameters of the P-POT-PDRR security system model by continuously collecting execution feedback and optimizing strategy rules. The collaboration of a safety system is improved; the intelligent level is higher; the threat processing time is shortened, the loss caused by attacks is reduced, and the response efficiency is better; and the method has good expandability and compatibility.
Owner:SHENZHEN Y& D ELECTRONICS CO LTD

Management software security maintenance method based on Internet information technology

The invention discloses a management software security maintenance method based on an internet information technology, which belongs to the technical field of data security and comprises the steps of block chain patch management, zero-trust architecture identity verification and access control, vulnerability response and repair and machine learning and dynamic behavior analysis. The technical problems of opaque patch management, low vulnerability response efficiency and insufficient unknown threat protection in traditional network security management are solved, patch tampering and malicious software invasion are effectively prevented, the security of intranet resources is improved, the vulnerability response speed is increased, the requirement for manual intervention is reduced, and the security of the intranet resources is improved. The protection capability of the system to novel attacks is enhanced, the complexity in the identity verification process is greatly reduced, the user experience is improved, the expansion range of potential attacks is reduced, and the flexibility and expandability of the system are enhanced.
Owner:NANJING XIAOZHUANG UNIV

LLM-based 6G network automatic security processing method and system

The embodiment of the invention provides an LLM-based 6G network automatic security processing method and system. The method is applied to the field of network security intelligent protection, and comprises the following steps: acquiring a network data stream, generating a structured log, extracting features, inputting the features into an intrusion detection model to identify attack behaviors, performing format conversion on a result to generate an LLM model, inputting the LLM model, and reasoning to obtain a network security disposal strategy. And extracting key fields, performing structured packaging, uploading the key fields to a block chain to complete evidence storage and integrity verification, and finally executing corresponding security control operation according to a strategy. According to the scheme, intelligent identification and automatic processing of network attacks are realized, after key fields are extracted, the structured strategy data are generated and uploaded to the block chain system for evidence storage and verification, traceability and data integrity of the processing process are ensured, network defense control which is automatic, high in security and timely in response can be realized, and the network attack processing efficiency is improved. And the intelligent and credible level of network security management is obviously improved.
Owner:TERMINUSBEIJING TECH CO LTD

Network security multi-mode intelligent detection method and device, equipment and storage medium

The invention provides a network security multi-mode intelligent detection method, device and equipment and a storage medium, and relates to the technical field of network security management.The detection method comprises the steps that static feature data, dynamic network flow data and time sequence behavior mode data of network boundary equipment are collected; performing multi-modal fusion analysis on the static characteristic data, the dynamic network flow data and the time sequence behavior mode data to generate a comprehensive risk result; determining whether to trigger a preset blocking sandbox mechanism based on the comprehensive risk result; and when a preset sandbox blocking mechanism is triggered, starting a preset verification process, performing simulation verification according to the comprehensive risk result, the dynamic network flow data and the time sequence behavior mode data to obtain a verification result, and performing real-time blocking operation according to the verification result to ensure network boundary security. According to the method, the limitation of traditional single data source detection is broken through, and the lag mode of traditional artificial log auditing is thoroughly changed.
Owner:GUO WANG ZHE JIANG SHENG DIAN LI YOU XIAN GONG SI CI XI SHI GONG DIAN GONG SI

Data security storage method adaptive to network security prevention and control

The invention belongs to the technical field of network security management and control, and particularly relates to a data security storage method adaptive to network security prevention and control, which comprises the steps of data acquisition, multi-dimensional feature extraction, optimal prevention and control strategy generation, hierarchical encryption storage, abnormal behavior traceability and dynamic isolation response. According to the system, illegal data injection risks are blocked from an entrance through a source data authentication acquisition module, multi-dimensional effective features of data are extracted through a multi-dimensional feature purification module, the multi-dimensional effective features and real-time network threat situations are fused through a prevention and control strategy adaptation module, and an optimal prevention and control strategy is screened by quantifying the adaptation degree; the hierarchical encryption storage module reasonably distributes storage hierarchies and executes differential encryption and hierarchical backup, the abnormal behavior traceability module accurately identifies abnormal behaviors, and the dynamic isolation response module executes hierarchical isolation and triggers emergency response and strategy optimization, so that full-life-cycle safety management and control of data from collection, storage to access is realized, and the safety of data storage is improved. And the prevention and control accuracy and the system operation efficiency are both considered.
Owner:HENAN SHENGSHI TECH CO LTD

Dynamic encryption network security management system based on federal learning

The invention relates to the technical field of network security management, and discloses a federated learning-based dynamic encryption network security management system, which comprises a network data acquisition module, a federated learning processing module, a security state monitoring module and the like. The network data acquisition module acquires flow and encryption state data in real time, and generates a characteristic value and encryption strategy dynamic adjustment set; the federal learning processing module generates a personalized encryption strategy according to the traffic characteristic value; the safety state monitoring module screens abnormal safety data; the strategy matching module determines a target adjustment strategy through multi-dimensional matching; the strategy adjustment module drives the encryption engine to correct the strategy; and the strategy self-learning module updates the strategy correction factor based on the feedback data. The system realizes dynamic encryption strategy adjustment and self-optimization, improves the intelligence and self-adaptive capability of network security protection, and is suitable for distributed network security management.
Owner:BEIJING DUOYAN SILICON VALLEY TECH DEV CO LTD

Abnormal behavior pattern recognition method and system applied to network security

The invention provides an abnormal behavior pattern recognition method and system applied to network security, and the method comprises the steps: firstly obtaining a multi-source network behavior data set containing a network flow record, a user operation sequence and a system state log, and then constructing a behavior context dependency graph based on the multi-source network behavior data set, the method comprises the following steps: determining a network behavior entity and a context association relationship thereof, performing pattern recognition on the network behavior entity in a behavior context dependency graph, extracting a plurality of behavior patterns, performing anomaly detection on a pattern recognition result and the graph in a cooperative manner, and generating an abnormal behavior pattern recognition result containing abnormal information; and finally, generating a dynamic response strategy based on an abnormal behavior pattern recognition result, and deploying the dynamic response strategy to a network security management platform to execute security protection operation, thereby improving the accuracy and timeliness of network security protection.
Owner:CHENGDU BINGJIAN INFORMATION TECH CO LTD

Network management authorization security management method and system for electric power communication network

The invention discloses a network management authorization security management method and system for an electric power communication network, and relates to the technical field of network security management. The method comprises the following steps: constructing a layered block chain network architecture; a user request is received, dynamic risk assessment is performed, a multi-factor identity authentication process is triggered, and after identity authentication is passed, an intelligent contract verifies the permission and generates a minimum permission access token; and the client accesses the token by means of the minimum authority, establishes an under-chain state channel, exchanges operation instructions and logs under the chain during the session, submits the aggregated hash values and the final states of all the operation logs to the slave block chains for evidence storage when the session is ended, and regularly anchors the state abstract of each slave block chain by the master block chain, so that the state abstract of each slave block chain is obtained. And completing global auditing traceability. The technical problem that in the prior art, network management operation authorization management of an electric power communication network lacks safety and traceability is solved, and the technical effects of improving the safety and credibility of network management operation authorization and achieving traceability of the whole operation process are achieved.
Owner:BENXI POWER SUPPLY COMPANY OF STATE GRID LIAONINGELECTRIC POWER SUPPLY

Network security threat perception and adaptive defense system based on artificial intelligence

The invention belongs to the technical field of network security management and control, and particularly relates to a network security threat perception and adaptive defense system based on artificial intelligence. Comprising a data acquisition preprocessing module, a threat feature intelligent mining module, a threat situation comprehensive evaluation module, a self-adaptive defense strategy generation module, a defense effect dynamic feedback module and a background supervision terminal. The data acquisition and preprocessing module acquires various data from a network environment and performs related preprocessing operation, the threat feature intelligent mining module mines potential network security threat features, and the threat situation comprehensive evaluation module comprehensively evaluates the network security threat situation. The self-adaptive defense strategy generation module generates a self-adaptive defense strategy based on the threat level and the influence range, and the defense effect dynamic feedback module monitors and evaluates the implementation effect of the self-adaptive defense strategy in real time, thereby providing an omnibearing, intelligent and self-adaptive guarantee for network security.
Owner:YALONG RIVER HYDROPOWER DEV CO LTD

Anomaly detection based on ensemble machine learning model

A security platform employs a variety techniques and mechanisms to detect security related anomalies and threats in a computer network environment. The security platform is ā€œbig dataā€ driven and employs machine learning to perform security analytics. The security platform performs user / entity behavioral analytics (UEBA) to detect the security related anomalies and threats, regardless of whether such anomalies / threats were previously known. The security platform can include both real-time and batch paths / modes for detecting anomalies and threats. By visually presenting analytical results scored with risk ratings and supporting evidence, the security platform enables network security administrators to respond to a detected anomaly or threat, and to take action promptly.
Owner:CISCO TECHNOLOGY INC

Network security situation visualization method

The invention provides a network security situation visualization method, and the method comprises the steps: S11, obtaining current network situation information in real time, screening the network situation information, obtaining situation information with visual features, and constructing a visual database; s12, performing feature extraction on the data in the visual database, analyzing the extracted features to distinguish security features and abnormal features, quantifying the network security state according to the abnormal features, and evaluating the threat degree of the network situation; s13, performing behavior detection on the data in the visual database, and identifying potential security threats in combination with threat degrees; and S14, carrying out visual display on analysis results of the steps S12 and S13. Through real-time acquisition, feature extraction, threat assessment and visual display, the problems of complex data, difficulty in threat identification and difficulty in understanding analysis results in network situation awareness are solved, and the efficiency and accuracy of network security management are improved.
Owner:HAINAN POWER GRID CO LTD

Wireless network security management method and system

The invention discloses a wireless network security management method and system. In the method, a system initialization module completes initialization, calls a key management module to generate signatures of a platform end and wireless equipment and encrypts asymmetric key pairs, and a wireless equipment management module records basic information of storage equipment. Before wireless equipment accesses, an authentication request containing first encryption information and first signature information is initiated through a request gateway module, after a platform end decrypts and verifies the signature to complete equipment authentication, second encryption information and second signature information are returned, and an equipment end decrypts and verifies the signature to complete bidirectional authentication. And network access is allowed in combination with the white list and the equipment registration state, and an administrator completes identity authentication and authority verification through the user authority management module and the request gateway module. After the equipment accesses the network, heartbeat communication and bidirectional authentication are carried out at regular intervals, equipment communication is controlled through a network communication strategy, and operation monitoring, situation analysis and log auditing are synchronously carried out. According to the invention, the problems of high access and operation and maintenance management security risk and the like in the prior art are solved.
Owner:JIANGSU NEW QUALITY INFORMATION TECH CO LTD +1

Evaluation method for network security management and control maturity

The invention relates to a network security management and control maturity evaluation method and device, computer equipment, a computer readable storage medium and a computer program product. Comprising the following steps: constructing a network security control maturity content model according to a preset index library and a preset domain structure; determining a key element corresponding to each three-level index; obtaining a binary evaluation result of the to-be-evaluated object in each key element; sequentially determining the score of each third-level index, the score of each second-level index and the score of each first-level index according to the binary evaluation result of each key element; determining a comprehensive score of the to-be-evaluated object according to preset weight information and the score of each first-level index; and according to the comprehensive score, mapping to obtain the maturity level of the to-be-evaluated object. The network security management and control maturity content model is clear in hierarchy, rigorous in logic and meticulous in particle; standardizing scoring standards, and realizing element quantification; differences of different domains are quantified, and the accuracy of network security management and control maturity evaluation is improved.
Owner:ELECTRIC POWER RES INST CHINA SOUTHERN POWER GRID CO LTD

Dynamic detection method and device for network assets

The invention discloses a dynamic detection method and device for network assets, and belongs to the technical field of network security management. The method comprises the steps of performing initialization analysis and environment matching processing on a detection instruction received by a system, and determining a task scanning object of a to-be-scanned asset; performing first dynamic detection on assets to be scanned according to the task scanning object to obtain port opening information of all survival assets; performing second dynamic identification on all survival assets according to the task scanning object and the port open information to obtain structured data of an open port; and performing fusion correction on the structured data according to a preset fingerprint database, and establishing a complete asset model of the to-be-scanned asset according to a correction result. According to the invention, the detection efficiency of network assets can be improved and complete detection information can be obtained.
Owner:BEIJING CHANGYANG TECH CO LTD

Intelligent response strategy adaptive generation method and system

The invention discloses an intelligent response strategy adaptive generation method and system, and relates to the technical field of network security. The method comprises the following steps: calling an information confrontation sample, and mining a causal chain set based on a network attack scene; according to the causal chain set, constructing a strategy generator and deploying the strategy generator in a network security center; the method comprises the following steps: performing real-time operation monitoring by taking a network attack element as an identification target, triggering a strategy generator, executing a multi-step decision, and determining a target response strategy, the multi-step decision comprising first causal matching of the triggering of the network attack element and the response strategy, and second judgment positioning based on strategy fitness; third combination optimization based on strategy point combination optimization; and performing network security management according to the target response strategy. The technical problem that in the prior art, network attack response strategy generation depends on a static rule, and consequently the response strategy is not accurate and effective enough is solved, and the technical effects that the self-adaptive response strategy is intelligently generated through multi-step decision making, and the network security protection effect is improved are achieved.
Owner:CHINA SOUTHERN POWER GRID COMPANY

Time fine-grained network traffic identification method and system

The invention discloses a time fine-grained network flow identification method and system, and belongs to the technical field of communication networks, and the method comprises the steps: firstly collecting a data flow generated by a communication data network, and compressing the data flow to obtain compressed network flow data; performing segmentation and data cleaning according to the quintuple, standardizing the length of the network flow data of each flow, and converting the standardized network data flow into a gray image in a binary form; and finally, cooperatively carrying out network traffic joint identification on the generated grayscale image through an HMAT algorithm and a network traffic identification method combined with LSTM improved space-time vision Transform, and obtaining an identification result. The method not only improves the precision and efficiency of traffic classification, but also can adapt to diversified requirements in a complex network environment in real time, and provides powerful technical support for network security management and service quality optimization.
Owner:NANJING UNIV OF POSTS & TELECOMM