Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

101 results about "Network security situation awareness" patented technology

Network security situation awareness and analysis platform based on AI

The invention discloses a network security situation awareness and analysis platform based on AI, and relates to the technical field of network security situation awareness and analysis, and the platform comprises a multi-source data collection module which integrates flow, logs, assets and threat intelligence data, and carries out encryption transmission and standardization; the data preprocessing module purifies and optimizes data, and guarantees data quality and sensitive information security; the AI situation awareness analysis module extracts features through a deep learning model, dynamically evaluates the situation and identifies threats; the threat early warning and decision-making module triggers graded early warning and generates a targeted emergency response scheme; the visual display and interaction module displays information in multiple dimensions and supports query and report generation; and the data storage and tracing module adopts a mixed storage architecture, so that the data security and traceability are ensured. The platform integrates multi-source data and realizes situation accurate perception and intelligent decision by means of an AI technology; the early warning is accurate, the visual interaction is convenient, and the intelligent and efficient level of network security protection is comprehensively improved.
Owner:HUNAN CONGMAO TECH CO LTD

Network security situation awareness method and system and computer equipment

The invention provides a network security situation awareness method and system and computer equipment, and belongs to the technical field of network security. The method comprises the following steps: collecting and standardizing multi-source heterogeneous security data; constructing and dynamically updating a network asset and vulnerability knowledge graph; performing tactical labeling on the security event based on tactical, technology and process behavior model libraries to form a current attack context state; mapping the current state into a knowledge graph to deduce a potential subsequent attack path; performing quantitative risk assessment on the path, and calculating an initiation probability and a potential risk value; outputting situation awareness information containing the path and the probability and risk value thereof; and dynamically determining a key area needing to be updated preferentially in the knowledge graph according to an evaluation result, and triggering incremental updating. According to the method, the crossing from static monitoring to dynamic prediction is realized, the attack path can be actively deduced, quantitative risk assessment is carried out, meanwhile, the real-time performance of the knowledge graph is guaranteed through a focusing updating mechanism, and the initiative and accuracy of network security protection are improved.
Owner:SICHUAN RUIFANGDA TECHNOLOGY CO LTD

Network security situation awareness method based on artificial intelligence

The invention discloses a network security situation awareness method based on artificial intelligence, and the method comprises the following steps: collecting multi-source heterogeneous data, and generating a standardized data set; spatial-temporal feature decoupling is carried out, and spatial-temporal dimension features are separated; fusing the time-space cross attention, and outputting a fused time-space feature vector; constructing a causal inference engine, and outputting a dynamic causal graph and an anti-fact inference result set; constructing a dynamic risk propagation model, and outputting a whole asset risk value matrix and a risk propagation path diagram; generating a situation quantization matrix, constructing an adversarial training decision network, and outputting a defense strategy set verified by adversarial training; automatically generating a strategy; and a man-machine cooperative verification closed loop is realized. According to the method, dynamic reconstruction of a threat propagation path is realized through spatial-temporal feature decoupling and a causal reasoning engine, and a risk positioning error is reduced; and the adversarial training decision network is combined, so that the misjudgment rate of the defense strategy in the simulation APT attack test is reduced.
Owner:BEIJING BEILONG YUNHAI NETWORK DATA TECH CO LTD

Network security situation awareness method and system

The invention relates to the technical field of network security monitoring, and discloses a network security situation awareness method and system, and the method comprises the steps: collecting a multi-source heterogeneous log, carrying out the standardized analysis, and obtaining log event data; performing real-time analysis by utilizing a dynamic baseline association engine based on the log event data to obtain log association alarm data, analyzing a triple from the log association alarm data, constructing a basic knowledge graph based on the triple, performing rule reasoning and embedded reasoning, and integrating reasoning results to form a situation-enhanced security situation knowledge graph; threat data are extracted according to the security situation knowledge graph, the threat data are optimized in combination with a graph neural network GAT to obtain a final network attack threat value, network security situation awareness is carried out based on the network attack threat value, and the threat data comprise comprehensive criticality and an attack influence range. According to the invention, the efficiency and effect of network security management can be improved.
Owner:TONGFANG KNOWLEDGE DIGITAL PUBLISHING TECH CO LTD

Network security situation awareness method based on artificial intelligence

The invention provides a network security situation awareness method based on artificial intelligence, and relates to the technical field of network security. Real-time monitoring and multi-source data fusion analysis are performed on a network communication behavior, a host operation state, threat alarm information and a relationship between vulnerabilities and a topological structure; constructing a threat intensity parameter, a behavior anomaly rate parameter, a vulnerability exposure degree parameter and a traffic anomaly density parameter, and calculating a risk potential energy index to realize quantitative evaluation of a network risk state; introducing an attack chain dynamic coupling index to perform dynamic analysis on a multi-stage attack evolution trend, and judging an attack chain formation risk; depicting an abnormal flow distribution concentration degree through a risk propagation convergence entropy index, and identifying concentrated penetration and critical path breakthrough risks; and defense strategies such as risk tracing, attack chain blocking and key path reinforcing are given, so that accurate recognition, trend prediction and adaptive defense of complex network attacks are realized.
Owner:CHENGDU RUIDIOU TECH CO LTD

Remote sensing satellite network security situation awareness method and system with dual prevention mechanisms

The invention discloses a remote sensing satellite network security situation awareness method and system with dual prevention mechanisms, and the method comprises the steps: obtaining multi-source heterogeneous data from a remote sensing satellite ground system network, and generating a structured data set through cleaning, denoising and standardization processing; and according to the structured data set, recording network assets by adopting an asset identification algorithm, and generating a risk thermodynamic diagram of the network assets through a Bayesian network model and an entropy weight method. And according to the risk thermodynamic diagram and the structured data set, adopting a deep learning model to detect abnormal traffic and behaviors, and generating a hidden danger list marked with priorities through a general vulnerability scoring standard and a threat intelligence library. And according to the risk thermodynamic diagram and the hidden danger list, constructing a dynamic security situation map by adopting a graph database and a community discovery algorithm. Therefore, the real-time fusion capability of multi-source heterogeneous data is improved, a dynamic attack chain reasoning mechanism is enhanced, and collaborative decision-making of risk early warning and hidden danger treatment is realized.
Owner:NAT SATELLITE METEOROLOGICAL CENT

Network security situation awareness method based on Transform and time sequence prediction

The invention belongs to the technical field of network security, and discloses a Transform and time sequence prediction-based network security situation awareness method, which comprises the following steps of: performing multi-level feature engineering on traffic data subjected to quality monitoring, and extracting three layers of 78-dimensional features; a situation assessment model based on Transform is constructed, and continuous situation scores are output through association between multi-head self-attention learning features; the continuous situation scores are aggregated according to a time window to form a situation score sequence, and a future situation is predicted by a mixed architecture of a Transform encoder and an LSTM decoder, so that coupling cooperation of evaluation and prediction is realized. According to the method, the real-time performance is guaranteed, meanwhile, good engineering practicability is achieved, and the flow record is converted into the situation scoring sequence with remarkable autocorrelation through window aggregation, so that the short-time prediction stability and learnability are improved.
Owner:NANJING UNIV OF POSTS & TELECOMM

Intrusion situation prediction method based on SEA-DDQN adaptive reinforcement learning

The invention belongs to the technical field of network security situation awareness, and discloses an intrusion situation prediction method based on SEA-DDQN adaptive reinforcement learning, and the method comprises the following steps: obtaining a network flow data set; preprocessing the obtained network flow data set to obtain a standardized data set; and constructing a deep attention Q network SEA-DDQN model based on double values, and carrying out network security intrusion situation prediction ISP to realize an ISP process. According to the intrusion situation prediction method based on SEA-DDQN adaptive reinforcement learning, through continuous interaction with a traffic environment, the prediction capability is continuously improved, so that the model can flexibly cope with complex and continuously changing threat scenes; the SEA-DDQN uses the advantages of reinforcement learning to optimize the adaptivity and decision making process of the model, thereby enhancing the anti-interference capability of the model in a dynamic environment.
Owner:CHENGDU UNIV OF INFORMATION TECH

Photovoltaic power station network security situation awareness and early warning method and system

The invention relates to the technical field of network security situation awareness and early warning, and discloses a photovoltaic power station network security situation awareness and early warning method and system, and the method comprises the steps: carrying out the multi-source heterogeneous data collection of a photovoltaic power station and a social network, and carrying out the distributed preprocessing and feature extraction of the collected data, carrying out weighted fusion analysis on the comprehensive feature data through a situation awareness model, predicting potential attacks through an attack prediction model, calculating a network security situation in real time through a deep belief network, and carrying out automatic attack blocking by a centralized control center and a plant station operation and maintenance terminal; encryption protection is carried out through a forward isolation device and a VPDN tunnel technology. According to the invention, situation awareness and risk prediction are carried out through a deep learning algorithm, automatic attack blocking and headquarters-plant-station intensive management and control are realized in combination with a dynamic early warning mechanism, a trapping system and a block chain technology, and the monitoring, early warning and protection capabilities of the network security of the photovoltaic power station are significantly improved.
Owner:DATANG KUNYU CLEAN ENERGY CO LTD +1

Network security situation awareness method and system based on deep learning

The invention discloses a network security situation awareness method and system based on deep learning, and the method comprises the steps: generating a time-space sequence data set through integrating a multi-source flow log and a behavior record, extracting the abnormal signal intensity, and generating an embedded vector set representing attack multidimensional through employing a graph representation learning method; and when the abnormal signal intensity exceeds a threshold value, mining time sequence relevance through a sequence analysis model, judging a hidden threat evolution path, updating complex attack chain representation in real time by utilizing a dynamic tracking mechanism, generating future threat probability distribution by fusing a risk prediction method, and determining a high-risk threat priority sequence. For high-risk threats, an early warning mechanism is activated through infrastructure influence assessment, a safety guarantee protocol is integrated, a protection layer is applied, and enhanced network defense configuration is generated. According to the embodiment, through integration of spatio-temporal data fusion, dynamic threat tracking and risk prediction, the detection precision and response speed of hidden threats are remarkably improved, and the safety of key infrastructures is guaranteed.
Owner:HUNAN JIEYIXIN TECH CO LTD

Unknown attack detection method and system for intelligent network security situation awareness

The invention discloses an unknown attack detection method and system for intelligent network security situation awareness, and the method comprises the steps: obtaining multi-dimensional data of a power grid monitoring system, carrying out the data preprocessing, carrying out the network attack preliminary detection of the multi-dimensional data through a pre-built network security situation awareness framework, and outputting suspected attack data, the method comprises the steps of performing data training on historical attack data through an improved OCN open set classification network, identifying attack features of each known attack type, performing semantic similarity calculation on the attack features and suspected attack data, performing attack feature mapping and clustering on the suspected attack data based on semantic similarity, and obtaining an unknown attack feature clustering result. And according to the unknown attack clustering result, carrying out attack type classification on unknown attacks in the suspected attack data to obtain an unknown attack detection result. The method has the effects of detecting unknown attack means in time, effectively reducing the risk that the power grid system suffers from network attacks and guaranteeing safe and stable operation of the power grid system.
Owner:CHINA DATANG CORPORATION SCIENCE AND TECHNOLOGY GENERAL RESEARCH INSTITUTE +1

Network security situation awareness method based on artificial intelligence

The invention relates to the technical field of network security, in particular to a network security situation awareness method based on artificial intelligence, which comprises the following steps: deploying probes on a plurality of key link nodes of a network, and acquiring a specific type of network basic maintenance message flowing through the node; based on the obtained message, microcosmic time sequence characteristics of the message are extracted, and a first time sequence signal is formed; comparing the first time sequence signal with a pre-stored node reference time sequence signal, executing collaborative deviation calculation, and generating a collaborative deviation coefficient; and based on the collaborative deviation coefficient, determining a local vibration intensity value of the node, converging local vibration intensity values of a plurality of nodes in the network, and executing spatial correlation fusion calculation. According to the method, anomaly detection is realized by analyzing the time sequence coordination rule of the network basic maintenance message, any abnormal condition damaging a normal coordination mode can be captured, and the recognition rate of unknown threats is improved.
Owner:NANJING KUNJIN NETWORK TECH CO LTD

Network security situation awareness and automatic response decision-making system based on AI

The invention discloses a network security situation awareness and automatic response decision-making system based on AI, and the system comprises a multi-source data processing module which is used for collecting multi-source data, executing time synchronization, field standardization and feature extraction, and generating a security event vector sequence; the situation modeling module is used for one-dimensional mapping and cross-source combination to form a situation representation vector; the attack relation modeling module is used for constructing a behavior combination structure and generating attack chain stage probability distribution and path contribution degree; the trend prediction module is used for extracting continuous time slices and inputting a time sequence modeling structure to generate a risk trend prediction result; the response strategy generation module is used for generating an optimal response action; and the closed-loop updating module is used for executing actions and updating parameters of each modeling module according to feedback information. According to the method, the multi-source security events are uniformly modeled based on the KAN network, so that collaborative updating of attack relation depiction, risk prediction and response generation is realized.
Owner:WUHAN DONGHU UNIV

Network defense system vulnerability simulation method based on generative adversarial network

The invention discloses a network defense system vulnerability simulation method based on a generative adversarial network. The method comprises the following steps: S1, generating a network security situation awareness data set; s2, obtaining a weighted attack path graph; s3, performing graph semantic coding on the weighted attack path graph, and mapping a condition vector set; s4, obtaining a converged candidate weak point configuration set; s5, generating a target weak point configuration list; s6, forming a weak bait cluster; and S7, collecting a detection behavior log aiming at the weak bait cluster in real time, generating an attacker interaction behavior data set by utilizing the behavior log and the transverse movement behavior log, updating a weighted attack path graph and a condition vector set based on the attacker interaction behavior data set, and performing online fine adjustment on the condition generative adversarial network to obtain a weighted attack path graph. And the step S5 and the step S6 are executed again. According to the invention, through comprehensive discrimination and constraint optimization, unification of high trapping value and low business risk is realized.
Owner:BEIJING RUISJINDA TECH CO LTD

Network security situation awareness and emergency response platform based on digital twinning

The invention discloses a network security situation awareness and emergency response platform based on digital twinning, which belongs to the technical field of network detection and comprises a data acquisition module for acquiring original data information related to network security; the data fusion and digital twinning modeling module is used for preprocessing the original data information, constructing a digital twinning virtual model and synchronously reflecting the processed data on the digital virtual model; the situation awareness analysis module is used for performing analysis based on the data in the virtual model environment so as to detect the network security state; and the response module performs corresponding emergency response based on the judgment result. According to the method, comprehensive analysis can be carried out by combining multiple pieces of data under the same influence layer to improve the detection accuracy, fusion analysis can be carried out by combining the data among multiple influence layers, the network security condition is judged according to the relevance among the influence layers, and the detection accuracy is further improved.
Owner:广东宜通衡睿科技有限公司

Network security situation awareness method and system based on large model and threat assessment

The invention relates to the technical field of network security, in particular to a network security situation awareness method and system based on a large model and threat assessment. The method comprises the following steps: firstly, acquiring and standardizing multi-modal security data in a cloud service environment in real time, distributing a behavior modal cluster for security event metadata through clustering analysis, and generating a security feature vector containing business semantics and behavior dynamic features based on a cluster center relocation technology; then constructing a local situation map reflecting asset topology and an access link by using a cloud security association model; semantic reasoning is performed on the atlas through a large language model, an attack intention is recognized, and an attack path is predicted; and finally, combining the path probability, the asset value and the vulnerability feature to quantitatively calculate a risk index, and automatically generating a response strategy. Semantic compression of massive logs is realized through modal clustering, and the calculation bottleneck of processing original data by a large model is overcome; and in combination with graph correlation and large model reasoning, the crossing from passive warning to active intention prediction is realized.
Owner:BEIJING ZHONGCHUANG HAISHENG TECHNOLOGY CO LTD

Information security comprehensive protection system of production enterprise

The invention discloses a production enterprise-oriented information security comprehensive protection system, which comprises a unified security management center, a region boundary protection module, a security computing environment module, a data full life cycle protection module, an authority management module, a threat active defense module and a network security situation awareness module, original dispersed and isolated safety capabilities are integrated into a linkage system through an integrated architecture of a unified safety management center and six functional modules through a unified interface / event bus, so that instant isolation and authentication of a transverse production control area, a management information area and a longitudinal remote operation and maintenance channel are realized, and the transverse penetration blocking rate is remarkably improved; role isolation and dynamic authorization are realized through the authority management module, the attack surface of a supply chain is greatly narrowed, the manual operation and maintenance workload is reduced by about six percent, and the overall safety toughness and operation efficiency of an enterprise are remarkably improved.
Owner:HENGTONG PRECISION COPPER FOIL TECHNOLOGY (DEYANG) CO LTD

A centralized control station network security situation awareness method and system

This application proposes a method and system for network security situation awareness at a centralized control station, belonging to the field of network security communication technology. The method includes: acquiring multi-source operational datasets corresponding to each sensing node in the centralized control station's sensing node set; extracting multi-dimensional feature vectors from each sensing node and performing feature offset analysis to obtain multi-dimensional offset feature vectors; calculating the degree of newness index of each sensing node; classifying the sensing node set into multiple levels by analyzing the degree of newness index to obtain multi-level sensing layers; constructing corresponding multi-level attack behavior detection models; and calling the multi-level attack behavior detection models to perform attack behavior risk detection on sensing nodes belonging to each level of sensing layer. By adaptively hierarchically modeling based on the degree of newness of sensing nodes, targeted attack behavior detection strategies are adopted for sensing nodes with different degrees of newness, thereby improving the accuracy and timeliness of network security situation awareness at the centralized control station in scenarios of dynamic node expansion.
Owner:BEIJING KEDONG ELECTRIC POWER CONTROL SYST CO LTD +2

A method and device for network security situation awareness

This application relates to the field of network situational awareness technology, and discloses a method and device for network security situational awareness. The method includes: identifying regulatory entities and collecting abnormal events; identifying interactive and operational behaviors as risk characteristics; constructing a first risk identification model and deploying it on an edge terminal; collecting the type and sensitivity attributes of the regulatory entities; dynamically forming regulatory assistance pairs based on the attributes; generating a second risk identification model by weighted averaging of the parameters of the first model based on the regulatory assistance pairs and deploying it in the cloud; real-time interactive data is preferentially screened by the cloud-based second model; if a risk is identified, a structured report is generated and distributed; if not identified, it is reviewed by the first model at the edge terminal. This application achieves distributed intelligent perception with cross-domain collaboration and data not leaving the domain, solving the model bias and centralized delay problems caused by insufficient samples of a single entity, and significantly improving detection accuracy, response efficiency, and collaborative defense capabilities in low-sample scenarios.
Owner:STATE GRID BEIJING ELECTRIC POWER CO

Network security situation awareness method and system based on deep learning

The invention relates to the field of network security, and discloses a network security situation awareness method and system based on deep learning, and the method comprises the following steps: obtaining multi-source network data; extracting time feature representation of nodes in the dynamic space-time diagram sequence through a multi-scale time feature extraction network; extracting spatial feature representation of the nodes through a graph neural network; fusing the time feature representation and the spatial feature representation; constructing a decoupling encoder based on the information bottleneck; and performing anomaly detection and attack path tracing based on the time hidden variable, the space hidden variable and the coupling hidden variable. By constructing a multi-scale time feature extraction network and introducing a dynamic receptive field adjustment mechanism, space-time coupling features are separated into a time hidden variable, a space hidden variable and a coupling hidden variable, and coupling information is comprehensively utilized during anomaly detection to improve detection precision. And an attack propagation path is accurately reconstructed based on pure spatial features during attack path tracing.
Owner:若昊新程(北京)科技有限公司

A border-aware method for few-shot class incremental malicious traffic classification

PendingCN122661009AIncremental processInterference (communication)
The application relates to a boundary perception method for few-shot class incremental malicious traffic classification, relates to the technical field of network security, improves the stability of few-shot new class representation, reduces the influence of the class increment process on the learned traffic representation, alleviates the classification score bias between the basic classes and the new classes, and improves the unified identification capability of all seen classes. Selective correction is carried out for the high-risk local class boundary, interference to the stable classification region and additional calculation overhead are reduced. In the scene of encrypted malicious traffic with invisible load content, the distinguishing capability of similar communication behavior traffic is improved. The application supports multi-round new class access and multi-agent cooperation, and adapts to the continuous evolution of the network security situation awareness demand.
Owner:QILU UNIVERSITY OF TECHNOLOGY (SHANDONG ACADEMY OF SCIENCES) +1

Self-adaptive network security situation awareness method and device combined with online learning

The invention provides a self-adaptive network security situation awareness method and device combined with online learning, and the method comprises the steps: collecting real-time network state data and system load index data of a preset data source, carrying out the preprocessing of the data to form a multi-modal time sequence segment, inputting a pre-training time sequence data prediction model activated by employing Monte Carlo Dropout through a sliding window, and carrying out the prediction of the real-time network state data and system load index data. The method comprises the following steps of: calculating a prediction value of a next time period, outputting a prediction value and an uncertainty quantity of the next time period, calculating a threat probability through historical residual probability distribution fitting, realizing double-index risk assessment based on a preset threshold interval system, dividing into three types of states, and finally, respectively triggering online learning, configuration maintenance or intervention disposal flow for different states. According to the method, by introducing uncertainty quantized double-index evaluation and state-driven online learning closed loop, crossing of network security situation awareness from static detection to dynamic self-adaption is achieved, and the two core problems of insufficient real-time performance and concept drift in an edge computing scene are effectively solved.
Owner:BEIJING UNIV OF POSTS & TELECOMM

A network traffic data denoising method, device, equipment and storage medium

The application discloses a network flow data denoising method, device and equipment and a storage medium, comprising: dividing an original network flow capture tensor into a first flow sample not subjected to a boundary attack and a second flow sample subjected to a boundary attack; training a variational autoencoder using the first flow sample, and encoding the second flow sample using the variational autoencoder; decoding an abnormal flow feature vector using a latent space prior probability model, and inputting a reconstructed network flow tensor and the original network flow capture tensor into a tensor decomposition model; and jointly training the variational autoencoder and the tensor decomposition model according to a reconstruction error between the low-rank reconstructed network flow tensor and the original network flow capture tensor until the reconstruction error satisfies a convergence condition, and outputting a denoised network flow tensor. The technical scheme of the embodiment of the application can effectively denoise network flow data and improve the overall level of network security situation awareness and governance.
Owner:EVERSEC BEIJING TECH

An artificial intelligence-based network security situation awareness method

The application discloses a network security situation awareness method based on artificial intelligence, comprising the following steps: collecting multi-source heterogeneous data to generate a standardized data set; decoupling space-time characteristics to separate space-time dimension characteristics; fusing space-time cross attention to output fused space-time characteristic vectors; constructing a causal reasoning engine to output a dynamic causal diagram and a counterfactual reasoning result set; constructing a dynamic risk propagation model to output a full asset risk value matrix and a risk propagation path diagram; generating a situation quantization matrix, constructing an adversarial training decision network, and outputting a defense strategy set verified by adversarial training; automatically generating a strategy; and man-machine collaborative verification closed loop. Through space-time characteristic decoupling and the causal reasoning engine, the application realizes dynamic reconstruction of a threat propagation path, reduces risk positioning error; in combination with the adversarial training decision network, the application makes the defense strategy have a reduced misjudgment rate in the simulation APT attack test.
Owner:BEIJING BEILONG YUNHAI NETWORK DATA TECH CO LTD

A Deep Learning-Based Network Security Situation Awareness Method and System

PendingCN122316711AData packArea network
This invention discloses a network security situation awareness method and system based on deep learning, relating to the field of deep learning technology. The method includes deploying a network security data acquisition component within a regional network to collect and parse network data packets, generating security event data; constructing a communication graph of network communication relationships based on the security event data, and embedding and mapping the communication edge features in the communication graph to generate communication edge embedding vectors as a vectorized representation of communication relationships; performing topology encoding based on the communication graph to generate position codes, and fusing the communication edge embedding vectors with the position codes to form fused edge vectors containing network topology information; introducing a multi-head attention mechanism to update the fused edge vectors to obtain the final edge vectors. This invention can not only more accurately identify and distinguish different types of attack behaviors, but also significantly improve the accuracy of network security status perception.
Owner:FUJIAN HUADIAN KEMEN POWER GENERATION CO LTD

A multi-dimensional based network security situation awareness system and method

The application discloses a kind of network security situation awareness system and method based on multidimension, it is related to network security situation awareness technical field, by abnormal flow comprehensive score calculation unit, in combination with abnormal score Sy, risk index Ry, data packet influence factor Iy and duration factor Dy, system can calculate accurate priority Py for each abnormal flow.This kind of comprehensive evaluation method makes system be able to consider the abnormal degree of flow, potential threat to system and duration comprehensively, improves the accuracy of abnormal flow detection.Through abnormal flow sequencing and security response triggering unit, system carries out descending order sequencing to the flow priority Py calculated, and classifies flow event according to priority threshold TPth.Through flow event according to priority sequencing, system can preferentially process the most urgent security threat, ensure that security personnel can respond to the most important event in time, improve response efficiency and processing timeliness.
Owner:NANTONG SHIPPING COLLEGE

Network security situation awareness method and system for signal creation environment

PendingCN122339805AIt innovationAttack
This invention relates to the field of network security technology, specifically to a network security situation awareness method and system for the domestic IT innovation environment. The method includes: extracting attack sub-links from a directed graph of entity relationships based on entity log data across different time periods; assigning risk indicators to each entity based on the attack sub-links; selecting predicted complete links for each attack sub-link; assigning association relationships to different attack sub-links based on the attack sub-links traversed by all predicted complete links, and determining the complete attack link accordingly; updating the entity's risk indicators based on the obtained complete attack links, and re-acquiring a more accurate complete attack link. This invention can intelligently associate and iteratively optimize attack fragments across time periods, effectively reconstructing the attacker's complete intent and improving the accuracy and reliability of situation awareness in the complex domestic IT innovation environment.
Owner:BEIJING GUANGYIN JIAYE TECHNOLOGY CO LTD

Energy private network security situation awareness method and system fusing internet of things and artificial intelligence

This application discloses a method and system for network security situation awareness of a private energy network integrating the Internet of Things (IoT) and artificial intelligence. The method includes: extracting frequency fluctuation feature sequences and communication interaction data based on the energy network's operating frequency signal and the network communication data stream; constructing a unified frequency-time reference axis for the entire network, mapping the communication interaction data to the frequency-time reference axis, and generating a frequency-anchored data sequence; performing semantic parsing on the energy network protocol messages in the communication interaction data, constructing a semantic representation of control commands and their expected physical effects model; performing semantic-temporal consistency verification to obtain semantic-physical coupling residuals; calculating the temporal reliability score of the communication data and identifying abnormal control behaviors; inputting the temporal reliability score and abnormal control behaviors into a preset situation assessment model, and outputting the network security situation value of the private energy network. This application improves the accuracy of network security situation detection.
Owner:GUIZHOU INST OF COAL SCI +1

Low-delay network security situation awareness system based on artificial intelligence

The invention discloses a low-delay network security situation awareness system based on artificial intelligence, which relates to the technical field of Internet of Things security and comprises a dynamic awareness topology reconstruction module, an edge gateway module, a terminal security agent module, a situation assessment and anomaly recognition engine module, a cross-domain linkage engine module and a situation early warning and visualization module. According to the method, a dynamic network security management closed loop is constructed, a terminal state is collected by a topology reconstruction module, a sensing cluster is established and topology is reconstructed, an edge gateway summarizes equipment operation data, a situation assessment and anomaly recognition engine analyzes and recognizes network anomaly and an attack link through model fusion, and a cross-domain linkage engine generates a protection instruction. And the terminal security agent executes operation, and the situation early warning and visualization module realizes global display and graded early warning, so that the problems of poor static topology adaptability, high data transmission delay and disjunction of situation assessment and protection response in the prior art are solved, and reliable security guarantee is provided for the dynamic network of the Internet of Things.
Owner:GUANGZHOU SIYUN DATA TECH CO LTD

Special protocol message cross-space semantic association reasoning method and system for power monitoring system

The invention discloses a special protocol message cross-space semantic association reasoning method and system for an electric power monitoring system, and aims to solve the problems that protocol analysis and system security events are isolated and advanced threats are difficult to associate in existing monitoring. The method comprises the following steps: jointly analyzing a protocol transmission time sequence through Fourier transform, wavelet transform and an intelligent time sequence prediction model, and constructing a fine-grained time characteristic baseline; a sensing agent is deployed on a host, a database, security and protection equipment and other layers, and formatted security events are collected; and designing an intelligent association engine fusing graph representation learning and rule reasoning, carrying out deep semantic association on an abnormal protocol mode and a cross-level security event, and realizing accurate threat alarm based on a business behavior full-link model of reinforcement learning self-optimization. According to the method, intelligent cross-space reasoning from network protocol microscopic abnormity to system macroscopic threat is realized, and the precision, the intelligent level and the adaptive capability of network security situation awareness of the intelligent substation are greatly improved.
Owner:ZHANGZHOU POWER SUPPLY COMPANY STATE GRID FUJIANELECTRIC POWER +1