Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

126 results about "Network security management" patented technology

Network security management includes various rules and procedures adopted by network administrators to ensure that unauthorized users do not obtain access. Security involves a host of policies that limit access. The process makes the network secure and protects and manages network operations.

Network space map surveying and mapping method and system based on multi-source data fusion

The invention discloses a network space map surveying and mapping method and system based on multi-source data fusion, and the method comprises the steps: obtaining a multi-source data set in a unified format based on network flow data, equipment information data and geographic position data; obtaining a network asset entity and an incidence relation graph thereof through entity identification and correlation analysis based on the multi-source data set with the uniform format; obtaining a network space three-dimensional map model through three-dimensional space mapping and visual rendering based on the network asset entity and the association relationship map thereof; based on the network space three-dimensional map model, performing dynamic updating according to the accessed real-time data flow to obtain real-time network space situation data; and obtaining a network security risk assessment result through anomaly detection and threat identification based on the real-time network space situation data. According to the invention, visual display and security situation awareness of the network space are realized, and a brand new decision support tool is provided for network security management.
Owner:WEBRAY TECH BEIJING CO LTD

Method, device and system for constructing attack graph, and storage medium

The embodiment of the invention provides a method, device and system for constructing an attack graph, and a storage medium, and relates to the technical field of network security. The method comprises the steps that based on a test case knowledge base of a target system, an attack graph information expansion algorithm is executed through a knowledge graph technology, and expanded information is obtained; utilizing the expanded information to construct an attribute attack graph of the target system; and carrying out attack path description on vulnerabilities of the target system based on the attribute attack graph. An attack graph information expansion algorithm is executed through a test case knowledge base based on a target system and by means of a knowledge graph technology, information needed for constructing an attack graph can be obtained, potential attack paths can be mined, the attack graph information is expanded, and then a comprehensive and accurate attribute attack graph is constructed. According to the method, effective description of the vulnerability attack path of the target system is realized, so that the constructed attack graph can reflect the security condition of the network system more truly, more scientific decision support is provided for network security management personnel, and the network security protection effect is improved.
Owner:STATE GRID SHANDONG ELECTRIC POWER CO +2

Anomaly detection based on ensemble machine learning model

A security platform employs a variety techniques and mechanisms to detect security related anomalies and threats in a computer network environment. The security platform is “big data” driven and employs machine learning to perform security analytics. The security platform performs user / entity behavioral analytics (UEBA) to detect the security related anomalies and threats, regardless of whether such anomalies / threats were previously known. The security platform can include both real-time and batch paths / modes for detecting anomalies and threats. By visually presenting analytical results scored with risk ratings and supporting evidence, the security platform enables network security administrators to respond to a detected anomaly or threat, and to take action promptly.
Owner:CISCO TECHNOLOGY INC

Public multi-mode cloud network resource software security enhancement method based on neural symbol fusion reasoning

The invention relates to a public multi-mode cloud network resource software security enhancement method based on neural symbol fusion reasoning, which comprises the following steps: an intermediate representation generation stage: generating and optimizing an intermediate representation of a program through a fine-tuned large language model, and establishing semantic mapping from a source code to a structured logic representation; in the symbol language conversion stage, the intermediate representation generated by the large language model is converted into a domain-specific language fact set which can be recognized in the symbol logic reasoning stage, and formal and logic expression of program semantics is achieved; and a symbol logic reasoning stage: matching the fact set with the rule base through a symbol logic reasoning engine, performing detection and verification according to the safety rule, generating a structured report, and feeding back a result for optimization. The method is suitable for security enhancement of various core software systems in a public cloud network multi-modal network environment, high-precision security analysis is carried out on cross-modal and cross-subsystem fragmented codes in a compiling-free environment, and verifiable technical support is provided for public cloud network security control.
Owner:PEKING UNIV

Network security situation awareness method and system

The invention relates to the technical field of network security monitoring, and discloses a network security situation awareness method and system, and the method comprises the steps: collecting a multi-source heterogeneous log, carrying out the standardized analysis, and obtaining log event data; performing real-time analysis by utilizing a dynamic baseline association engine based on the log event data to obtain log association alarm data, analyzing a triple from the log association alarm data, constructing a basic knowledge graph based on the triple, performing rule reasoning and embedded reasoning, and integrating reasoning results to form a situation-enhanced security situation knowledge graph; threat data are extracted according to the security situation knowledge graph, the threat data are optimized in combination with a graph neural network GAT to obtain a final network attack threat value, network security situation awareness is carried out based on the network attack threat value, and the threat data comprise comprehensive criticality and an attack influence range. According to the invention, the efficiency and effect of network security management can be improved.
Owner:TONGFANG KNOWLEDGE DIGITAL PUBLISHING TECH CO LTD

Method and device for constructing network security management and control platform, electronic equipment and storage medium

The invention belongs to the field of network security, and relates to a method and device for constructing a network security management and control platform, electronic equipment and a storage medium, and the method comprises the steps: constructing a P-POT-PDRR security system model; constructing an intelligent multi-agent system consisting of a sensing agent, an analysis agent, an execution agent and a collaborative scheduling agent; through multi-source network data acquisition, cleaning, fusion and asset map construction, perception of a network environment is realized. Constructing an AI intelligent analysis and threat identification engine; based on an analysis result and a predefined strategy, risk assessment, attack path prediction and automatic response decision are realized, and the threat disposal time is shortened; and iterating parameters of the P-POT-PDRR security system model by continuously collecting execution feedback and optimizing strategy rules. The collaboration of a safety system is improved; the intelligent level is higher; the threat processing time is shortened, the loss caused by attacks is reduced, and the response efficiency is better; and the method has good expandability and compatibility.
Owner:SHENZHEN Y& D ELECTRONICS CO LTD

LLM-based 6G network automatic security processing method and system

The embodiment of the invention provides an LLM-based 6G network automatic security processing method and system. The method is applied to the field of network security intelligent protection, and comprises the following steps: acquiring a network data stream, generating a structured log, extracting features, inputting the features into an intrusion detection model to identify attack behaviors, performing format conversion on a result to generate an LLM model, inputting the LLM model, and reasoning to obtain a network security disposal strategy. And extracting key fields, performing structured packaging, uploading the key fields to a block chain to complete evidence storage and integrity verification, and finally executing corresponding security control operation according to a strategy. According to the scheme, intelligent identification and automatic processing of network attacks are realized, after key fields are extracted, the structured strategy data are generated and uploaded to the block chain system for evidence storage and verification, traceability and data integrity of the processing process are ensured, network defense control which is automatic, high in security and timely in response can be realized, and the network attack processing efficiency is improved. And the intelligent and credible level of network security management is obviously improved.
Owner:TERMINUSBEIJING TECH CO LTD

Network security multi-mode intelligent detection method and device, equipment and storage medium

The invention provides a network security multi-mode intelligent detection method, device and equipment and a storage medium, and relates to the technical field of network security management.The detection method comprises the steps that static feature data, dynamic network flow data and time sequence behavior mode data of network boundary equipment are collected; performing multi-modal fusion analysis on the static characteristic data, the dynamic network flow data and the time sequence behavior mode data to generate a comprehensive risk result; determining whether to trigger a preset blocking sandbox mechanism based on the comprehensive risk result; and when a preset sandbox blocking mechanism is triggered, starting a preset verification process, performing simulation verification according to the comprehensive risk result, the dynamic network flow data and the time sequence behavior mode data to obtain a verification result, and performing real-time blocking operation according to the verification result to ensure network boundary security. According to the method, the limitation of traditional single data source detection is broken through, and the lag mode of traditional artificial log auditing is thoroughly changed.
Owner:GUO WANG ZHE JIANG SHENG DIAN LI YOU XIAN GONG SI CI XI SHI GONG DIAN GONG SI

Data security storage method adaptive to network security prevention and control

The invention belongs to the technical field of network security management and control, and particularly relates to a data security storage method adaptive to network security prevention and control, which comprises the steps of data acquisition, multi-dimensional feature extraction, optimal prevention and control strategy generation, hierarchical encryption storage, abnormal behavior traceability and dynamic isolation response. According to the system, illegal data injection risks are blocked from an entrance through a source data authentication acquisition module, multi-dimensional effective features of data are extracted through a multi-dimensional feature purification module, the multi-dimensional effective features and real-time network threat situations are fused through a prevention and control strategy adaptation module, and an optimal prevention and control strategy is screened by quantifying the adaptation degree; the hierarchical encryption storage module reasonably distributes storage hierarchies and executes differential encryption and hierarchical backup, the abnormal behavior traceability module accurately identifies abnormal behaviors, and the dynamic isolation response module executes hierarchical isolation and triggers emergency response and strategy optimization, so that full-life-cycle safety management and control of data from collection, storage to access is realized, and the safety of data storage is improved. And the prevention and control accuracy and the system operation efficiency are both considered.
Owner:HENAN SHENGSHI TECH CO LTD

Network management authorization security management method and system for electric power communication network

The invention discloses a network management authorization security management method and system for an electric power communication network, and relates to the technical field of network security management. The method comprises the following steps: constructing a layered block chain network architecture; a user request is received, dynamic risk assessment is performed, a multi-factor identity authentication process is triggered, and after identity authentication is passed, an intelligent contract verifies the permission and generates a minimum permission access token; and the client accesses the token by means of the minimum authority, establishes an under-chain state channel, exchanges operation instructions and logs under the chain during the session, submits the aggregated hash values and the final states of all the operation logs to the slave block chains for evidence storage when the session is ended, and regularly anchors the state abstract of each slave block chain by the master block chain, so that the state abstract of each slave block chain is obtained. And completing global auditing traceability. The technical problem that in the prior art, network management operation authorization management of an electric power communication network lacks safety and traceability is solved, and the technical effects of improving the safety and credibility of network management operation authorization and achieving traceability of the whole operation process are achieved.
Owner:BENXI POWER SUPPLY COMPANY OF STATE GRID LIAONINGELECTRIC POWER SUPPLY

Network security threat perception and adaptive defense system based on artificial intelligence

The invention belongs to the technical field of network security management and control, and particularly relates to a network security threat perception and adaptive defense system based on artificial intelligence. Comprising a data acquisition preprocessing module, a threat feature intelligent mining module, a threat situation comprehensive evaluation module, a self-adaptive defense strategy generation module, a defense effect dynamic feedback module and a background supervision terminal. The data acquisition and preprocessing module acquires various data from a network environment and performs related preprocessing operation, the threat feature intelligent mining module mines potential network security threat features, and the threat situation comprehensive evaluation module comprehensively evaluates the network security threat situation. The self-adaptive defense strategy generation module generates a self-adaptive defense strategy based on the threat level and the influence range, and the defense effect dynamic feedback module monitors and evaluates the implementation effect of the self-adaptive defense strategy in real time, thereby providing an omnibearing, intelligent and self-adaptive guarantee for network security.
Owner:YALONG RIVER HYDROPOWER DEV CO LTD

Anomaly detection based on ensemble machine learning model

A security platform employs a variety techniques and mechanisms to detect security related anomalies and threats in a computer network environment. The security platform is “big data” driven and employs machine learning to perform security analytics. The security platform performs user / entity behavioral analytics (UEBA) to detect the security related anomalies and threats, regardless of whether such anomalies / threats were previously known. The security platform can include both real-time and batch paths / modes for detecting anomalies and threats. By visually presenting analytical results scored with risk ratings and supporting evidence, the security platform enables network security administrators to respond to a detected anomaly or threat, and to take action promptly.
Owner:CISCO TECHNOLOGY INC

Wireless network security management method and system

The invention discloses a wireless network security management method and system. In the method, a system initialization module completes initialization, calls a key management module to generate signatures of a platform end and wireless equipment and encrypts asymmetric key pairs, and a wireless equipment management module records basic information of storage equipment. Before wireless equipment accesses, an authentication request containing first encryption information and first signature information is initiated through a request gateway module, after a platform end decrypts and verifies the signature to complete equipment authentication, second encryption information and second signature information are returned, and an equipment end decrypts and verifies the signature to complete bidirectional authentication. And network access is allowed in combination with the white list and the equipment registration state, and an administrator completes identity authentication and authority verification through the user authority management module and the request gateway module. After the equipment accesses the network, heartbeat communication and bidirectional authentication are carried out at regular intervals, equipment communication is controlled through a network communication strategy, and operation monitoring, situation analysis and log auditing are synchronously carried out. According to the invention, the problems of high access and operation and maintenance management security risk and the like in the prior art are solved.
Owner:JIANGSU NEW QUALITY INFORMATION TECH CO LTD +1

Dynamic detection method and device for network assets

ActiveCN121547379ATransmissionOpen portEngineering
The invention discloses a dynamic detection method and device for network assets, and belongs to the technical field of network security management. The method comprises the steps of performing initialization analysis and environment matching processing on a detection instruction received by a system, and determining a task scanning object of a to-be-scanned asset; performing first dynamic detection on assets to be scanned according to the task scanning object to obtain port opening information of all survival assets; performing second dynamic identification on all survival assets according to the task scanning object and the port open information to obtain structured data of an open port; and performing fusion correction on the structured data according to a preset fingerprint database, and establishing a complete asset model of the to-be-scanned asset according to a correction result. According to the invention, the detection efficiency of network assets can be improved and complete detection information can be obtained.
Owner:BEIJING CHANGYANG TECH CO LTD

Intelligent response strategy adaptive generation method and system

The invention discloses an intelligent response strategy adaptive generation method and system, and relates to the technical field of network security. The method comprises the following steps: calling an information confrontation sample, and mining a causal chain set based on a network attack scene; according to the causal chain set, constructing a strategy generator and deploying the strategy generator in a network security center; the method comprises the following steps: performing real-time operation monitoring by taking a network attack element as an identification target, triggering a strategy generator, executing a multi-step decision, and determining a target response strategy, the multi-step decision comprising first causal matching of the triggering of the network attack element and the response strategy, and second judgment positioning based on strategy fitness; third combination optimization based on strategy point combination optimization; and performing network security management according to the target response strategy. The technical problem that in the prior art, network attack response strategy generation depends on a static rule, and consequently the response strategy is not accurate and effective enough is solved, and the technical effects that the self-adaptive response strategy is intelligently generated through multi-step decision making, and the network security protection effect is improved are achieved.
Owner:CHINA SOUTHERN POWER GRID COMPANY

Network attack defense method and device, storage medium and server

The embodiment of the invention discloses a network attack defense method and device, a storage medium and a server, attack information sent by network security management equipment corresponding to a server side is received, and the attack information is information collected by the network security management equipment corresponding to the server side for a monitored network attack event; based on the attack information, determining a source network node corresponding to the network attack event, and generating a processing instruction for the network attack event; and sending the processing instruction to a network security management device corresponding to the source network node, so that the network security management device corresponding to the source network node carries out attack processing on the network attack event. Through analysis of attack information, a source network node initiating an attack behavior can be accurately positioned, then a processing instruction generated by a server directly instructs a network security management device corresponding to the node to execute an attack processing operation, and the mechanism can clean and eliminate attack traffic before the attack traffic enters an Internet public network.
Owner:CHONGQING ANT CONSUMER FINANCE CO LTD

Visual safety brain modeling and early warning platform of highway toll collection system

The invention belongs to the technical field of data safety, and particularly relates to a visual safety brain modeling and early warning platform of an expressway toll collection system, which comprises a data capturing module used for acquiring real-time interaction data and a toll station three-dimensional model of the expressway toll collection system, and constructing an expressway toll station panoramic three-dimensional model in a three-dimensional environment; the dynamic display module comprises a first floating information board, a second floating information board, a third floating information board, a fourth floating information board and a fifth floating information board; the early warning module is used for analyzing the real-time interaction data acquired by the data capturing module to find abnormal data and tracing an abnormal event; and the adjusting module provides a dynamic adjusting mechanism according to the matching result. According to the method, the distribution strategy is adjusted in real time to cope with changes of emergency situations and tasks, the empty window period occurring in the adjustment process is avoided as much as possible, and network security management vulnerabilities of the highway toll collection system can be prevented.
Owner:EAST CHINA JIAOTONG UNIVERSITY

A data management system and method applied to network security supervision

PendingCN122513138AData packData integrity
This invention discloses a data management system and method for network security supervision, relating to the field of network security management technology. It includes an evidence construction unit, a rule execution unit connected to the evidence construction unit, a dual-track evidence storage unit connected to both the evidence construction unit and the rule execution unit, and a display unit connected to the dual-track evidence storage unit. The invention deploys the evidence construction unit on network nodes, encapsulating evidence chain data packets based on 5-tuples and timestamps and calculating hash values ​​to ensure data integrity and traceability. The rule execution unit converts supervision regulations into executable code, calculates the results of evidence chain matching, and outputs the results. The dual-track evidence storage unit uploads the evidence hash values ​​to the blockchain via a first channel and the rule call records via a second channel, establishing a bidirectional cross-index to achieve dual evidence and behavior storage. The display unit retrieves data based on the cross-index for verification and visualizes the entire process, thus solving the problems of easily tampered evidence, opaque processes, and difficult-to-trace results.
Owner:GUANGDONG POWER GRID CO LTD +1

Power transmission network security management system

The invention relates to a power transmission network security management system, and the system comprises a final-stage conversion mechanism which is used for successively executing Wiener filtering processing and median filtering processing on a secondary conversion picture; and the model application device is used for intelligently identifying whether the field spacing distance between the grounding piece and the operation electrician is smaller than or equal to the safe spacing distance or not by adopting an AI identification model. The power transmission network security management system is intelligent in design and simple to operate and control. The image content capturing action can be executed on the replacement scene for replacing the strain insulator string so as to obtain and output the corresponding replacement scene picture, and the AI identification model is adopted to intelligently identify whether the field spacing distance between the grounding piece and the operation electrician is smaller than or equal to the safe spacing distance based on various visual information in the replacement scene picture; therefore, when a strain insulator string is replaced in a power transmission network, a reliable and safe distance between an operation electrician and a grounding body is maintained.
Owner:NANJING XIEJINYU ELECTRIC POWER TECHNOLOGY CO LTD

Method and system for positioning data stream with null domain name based on task ID

The invention relates to the technical field of network security management and flow analysis, and provides a method and a system for positioning a data flow with a null domain name based on a task ID, and the method comprises the steps: monitoring a synchronous message through a process A, and capturing network flow; the abnormal task ID is received through the process B, and a server IP list is determined according to the corresponding domain name of the abnormal task ID; filtering a Client Hello data stream of a target IP (Internet Protocol) from the captured message; judging whether each data stream carries a Server Name field or not; and counting the proportion of the data streams which do not carry the fields and have null domain names, and outputting an evidence message. The problems that traditional manual analysis is low in efficiency, poor in accuracy and high in personnel skill requirement are solved, and the network security management efficiency is remarkably improved.
Owner:SHANGHAI HENGWEI INTELLIGENT TECH CO LTD

Dynamic encryption network security management system based on federated learning

The application relates to the technical field of network security management, and discloses a dynamic encryption network security management system based on federal learning, which comprises network data acquisition, federal learning processing, security state monitoring and the like. The network data acquisition module acquires traffic and encryption state data in real time, generates characteristic values and an encryption strategy dynamic adjustment set; the federal learning processing module generates individualized encryption strategies according to the traffic characteristic values; the security state monitoring module screens abnormal security data; the strategy matching module determines a target adjustment strategy through multidimensional matching; the strategy adjustment module drives an encryption engine to correct the strategy; and the strategy self-learning module updates a strategy correction factor based on feedback data. The system realizes dynamic encryption strategy adjustment and self-optimization, improves the intelligentization and self-adaptive capacity of network security protection, and is suitable for distributed network security management.
Owner:BEIJING DUOYAN SILICON VALLEY TECH DEV CO LTD

Comprehensive safety index evaluation method based on multi-task learning

PendingCN121567423ASecuring communicationSecurity metricData set
The invention provides a comprehensive security index evaluation method based on multi-task learning, and belongs to the technical field of network security management, and the method comprises the steps: synchronously collecting original data from a plurality of heterogeneous security data sources; a multi-task learning neural network model is constructed, and the model comprises a shared feature coding network for outputting shared features; the at least two heterogeneous task decoding networks are used for respectively mapping the shared features into preliminary security assessment results with different attributes; the fusion network is used for carrying out weighted fusion on the preliminary security assessment result to generate a comprehensive security index; using the multi-source security data set to train the multi-task learning neural network model; and inputting real-time security data of a to-be-evaluated system into the trained model, and outputting a comprehensive security index. The method has the advantages that the shared feature coding network can extract high-level feature representations with commonality from different data sources, and feature engineering dependence for a single data source or a single task is avoided.
Owner:LUOHE POWER SUPPLY OF HENAN ELECTRIC POWER CORP

A secure identity authentication method for network switches based on remote AAA service

This invention relates to a secure identity authentication method for network switches based on remote AAA services, belonging to the field of network security management. The method includes the following steps: Step 1, network setup, configuring interconnection between network switches to ensure routing reachability between devices; Step 2, setting up an AAA server; Step 3, configuring policies in the network switches; Step 4, configuring policies in Active Directory. This invention establishes an AAA server, utilizes AD+RADIUS to provide remote access and identity authentication services, and controls network switch logins through remote management authentication, thereby improving the security protection capabilities of the network switches.
Owner:BEIJING INST OF COMP TECH & APPL

Low-delay network security situation awareness system based on artificial intelligence

The invention discloses a low-delay network security situation awareness system based on artificial intelligence, which relates to the technical field of Internet of Things security and comprises a dynamic awareness topology reconstruction module, an edge gateway module, a terminal security agent module, a situation assessment and anomaly recognition engine module, a cross-domain linkage engine module and a situation early warning and visualization module. According to the method, a dynamic network security management closed loop is constructed, a terminal state is collected by a topology reconstruction module, a sensing cluster is established and topology is reconstructed, an edge gateway summarizes equipment operation data, a situation assessment and anomaly recognition engine analyzes and recognizes network anomaly and an attack link through model fusion, and a cross-domain linkage engine generates a protection instruction. And the terminal security agent executes operation, and the situation early warning and visualization module realizes global display and graded early warning, so that the problems of poor static topology adaptability, high data transmission delay and disjunction of situation assessment and protection response in the prior art are solved, and reliable security guarantee is provided for the dynamic network of the Internet of Things.
Owner:GUANGZHOU SIYUN DATA TECH CO LTD

Dynamic security protection method and system based on behavior workflow and kalman filter

The application discloses a dynamic security protection method and system based on behavior workflow and Kalman filtering, and relates to the technical field of network security management and control.The application comprises the following steps: collecting multi-source heterogeneous original logs and performing standardized processing to obtain a standardized event stream; mapping the standardized event stream into an attack stage sequence, constructing and incrementally updating an attack semantic graph, and extracting attack progress observation values; establishing a state space model including attack progress and attack speed based on Kalman filtering, performing attack state estimation and trend prediction, and obtaining attack progress estimation and attack speed estimation; calculating threat urgency, and adjusting a two-way mandatory access control strategy based on the threat urgency classification. A dynamic security protection system capable of realizing real-time perception of attack process evolution, dynamic adjustment of access control strategy, high interpretability and strong adaptability is constructed, and deep coupling of attack semantic understanding, attack state estimation and access control strategy adjustment at the system level is realized.
Owner:SHENZHEN Y& D ELECTRONICS CO LTD

Artificial intelligence-based collaborative office network security management method and system and medium

The application discloses a collaborative office network security management method and system based on artificial intelligence and a medium, belongs to the technical field of artificial intelligence network security, and is used for solving the technical problem that when the existing collaborative office network has network abnormal conditions or network security events, the emergency mechanism mainly depends on manual intervention, and the response efficiency is low when data leakage or system paralysis is caused. The method comprises the following steps: through an edge computing node and based on an artificial intelligence engine architecture, performing edge preprocessing on initial office network data about adversarial samples to obtain a network feature matrix based on the initial office network data; through the artificial intelligence engine architecture, performing double-channel network anomaly detection processing on the network feature matrix to obtain network anomaly detection result data; and according to the network anomaly detection result data, performing corresponding network risk response actions and automatically generating a network anomaly solution strategy.
Owner:山东大通世纪实业有限公司

A network security management method and system based on big data models

This invention relates to the field of network security technology and discloses a network security management method and system based on a big data model, comprising: Step 1, converting multi-source heterogeneous data into graph nodes containing device entities, IP entities, and user entities, as well as interaction edges containing timestamps and relationship types; Step 2, constructing a dynamic evolution equation for an attack chain based on the graph nodes and interaction edges, wherein the equation includes attacker action parameters and defender action parameters; Step 3, using the state variables corresponding to the dynamic evolution equation of the attack chain, inputting them into a time fusion Transformer model to obtain the probability distribution of future attack action sequences. This invention employs a technical solution based on a differential game model to construct a dynamic evolution equation for the attack chain, a time fusion Transformer to predict attack action sequences, and meta-reinforcement learning to dynamically update defense strategies, achieving the technical effects of accurately modeling attack evolution paths, predicting attack behavior in advance, and generating adaptive defense strategies in real time.
Owner:BEIJING SUPER EXPLORATION TECH CO LTD

Local area network equipment network security early warning method based on zero-trust architecture

The invention discloses a local area network equipment network security early warning method based on a zero-trust architecture, relates to the technical field of network security, and realizes real-time security monitoring and early warning of terminal equipment in a local area network through technical means such as access request interception and processing, dynamic identity authentication, terminal behavior analysis and equipment security index evaluation. The method comprises the following steps: performing grouping processing on local area network access requests through an interception module, and constructing an access request sequence based on time, space and structural features; then, carrying out multi-factor dynamic identity authentication on the terminal equipment by utilizing a big data analysis module, and screening out safe and credible terminal equipment in combination with equipment behavior baseline and matching degree calculation; then, evaluating the current equipment safety index of the terminal equipment through the system log and the memory utilization rate data in the backtracking period; and finally, releasing or blocking the access request according to the security index threshold, and generating corresponding early warning information to provide decision support for network security management.
Owner:SICHUAN PUBLIC SUPERVISION CONSULTING CO LTD

Safety equipment log analysis method and device, electronic equipment and storage medium

The invention discloses a safety equipment log analysis method and device, electronic equipment and a storage medium. The method comprises the following steps: acquiring log content of security equipment; inputting the safety equipment log content into a preset large language model, processing the safety equipment log content through the large language model, and outputting target log content; wherein the format of the target log content is a JSON format. According to the technical scheme, diversified log formats are adapted based on the powerful generalization ability of the large language model, and newly accessed unknown security equipment and format changes caused by software version upgrading of the accessed security equipment are flexibly dealt with. Meanwhile, the requirement for manual intervention is reduced, the maintenance cost and the error rate are reduced, the accuracy of log analysis is improved, more complex log analysis tasks are supported, and more comprehensive support is provided for network security management.
Owner:CHINA MOBILE (XIONGAN) ICT CO LTD +3

Multi-dimensional network attack tracing and early warning system based on AI

The invention relates to the technical field of network security, in particular to an AI-based multi-dimensional network attack tracing and early warning system, which comprises a network security management center, a multi-source data acquisition module, an AI multi-dimensional analysis module, a defense matching module and an early warning operation module, the AI multi-dimensional analysis module comprises an attack identification sub-module, a path return sub-module and a source positioning sub-module; according to the method, through multi-source data fusion collection, feature missing caused by a single data dimension is avoided so as to reduce the missed judgment probability, meanwhile, the fusion model is adopted to recognize the attack type and intensity, the attack recognition accuracy is improved, the attack propagation graph is constructed, the attack source is accurately positioned, and the problems of low efficiency and poor accuracy of traditional tracing are solved; and meanwhile, graded early warning is generated based on risk grades, so that attacks with different severity degrees are enabled to obtain corresponding responses, automatic matching of defense strategies is realized, protection delay is avoided, and the active defense capability of network security is improved.
Owner:GUANGZHOU SIYUN DATA TECH CO LTD