Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

134 results about "Network security situation awareness" patented technology

Network security situation awareness method and system

The invention relates to the technical field of network security, in particular to a network security situation awareness method and system, and the method comprises the following steps: extracting a source IP address and a target IP address based on a network behavior record, carrying out the statistics of the number of used ports, the transmission direction and the time interval value, analyzing the direction change times and the time interval difference, and screening abnormal communication pairs. And generating an abnormal communication pair set. According to the invention, through analyzing port usage, transmission direction and time interval value, deeply mining communication features, screening abnormal communication pairs and improving identification accuracy, dividing a time sequence window, analyzing rate fluctuation and frequency distribution, locking an unstable time window, combining with a multi-dimensional data classification behavior mode, and extracting a switching path and priority, a multi-dimensional data classification behavior mode is combined. Potential threat paths are identified independently, global threat situations are identified through node interaction relation statistics and correlation analysis and an expansion range, threat assessment precision and efficiency are enhanced, and comprehensive and reliable risk protection capability is provided for network managers.
Owner:JIANGSU ZHOUQI DIGITAL TECH CO LTD

Network security situation awareness method and device for multi-source data fusion, equipment and medium

The invention relates to a network security situation awareness method and device for multi-source data fusion, equipment and a medium, and the method comprises the steps: respectively collecting kernel logs and network flow data, and carrying out the standardization processing to generate a communication data set; constructing a dynamic process link map, defining a communication type, frequency and data volume, and updating a topological relation in real time; a sliding time window is adopted to count communication time sequence characteristics, and abnormal signals deviating from normal distribution are screened in combination with a time sequence analysis technology; training a robustness classifier model through an adversarial sample enhancement technology, fusing a graph neural network to analyze a dependency relationship between processes, and filtering a false alarm signal; and the hidden channel is accurately identified and alarm information is generated in combination with a dynamic similarity threshold and a threat intelligence gain coefficient, so that the problems of insufficient multi-source data fusion, high false alarm rate of a static rule base, failure in detection of weak signals of the hidden channel and the like in a traditional method are solved. And the real-time perception and response capability of APT attacks in a complex network environment is improved.
Owner:MINXI VOCATIONAL & TECHN COLLEGE

Network security situation awareness and early warning method based on big data analysis

The invention relates to the technical field of network security, in particular to a network security situation awareness and early warning method based on big data analysis, and the method comprises the following steps: collecting multi-modal security data, and carrying out the noise reduction and normalization processing; constructing a high-dimensional security feature vector by using feature engineering; establishing an anomaly detection model based on physical constraints and a deep residual network; a self-adaptive loss optimization strategy training model is adopted, so that the detection accuracy is improved; through cross-domain transfer learning, model adaptability is optimized, and unknown attacks can be detected; future attack trends are analyzed in combination with historical data, and defense strategies are dynamically adjusted. Through combination of deep learning and big data analysis, the accuracy, real-time performance and adaptive capability of network security situation awareness are improved, unknown attacks and variant attacks can be effectively detected, the false alarm rate is reduced, the security protection capability is enhanced, and the method is suitable for a security defense system in a complex network environment.
Owner:SHANDONG ENERGY GRP CO LTD +1

Network security situation awareness and dynamic analysis method based on graph neural network

The invention discloses a network security situation awareness and dynamic analysis method based on a graph neural network, and the method comprises the following steps: S1, collecting network related data, and constructing a dynamic security knowledge graph; s2, preprocessing the collected data to generate a node feature matrix; s3, based on the node feature matrix, generating a node embedding representation through an improved graph neural network and a graph attention mechanism, and optimizing the node embedding representation in combination with the graph attention mechanism; s4, establishing a time sequence prediction model based on the improved support vector regression model, and identifying potential abnormal behaviors and security threats; s5, evaluating the identified security threat, and predicting the risk level of the security threat; s6, generating a response strategy according to a security threat assessment result; and S7, executing the response strategy. According to the method, the improved graph neural network and the support vector regression model are utilized to carry out network security situation awareness and dynamic analysis, and the method has efficient and accurate security threat identification and adaptive response capabilities.
Owner:SHANDONG LANGGU INFORMATION TECH CO LTD

Network security situation awareness and analysis platform based on AI

The invention discloses a network security situation awareness and analysis platform based on AI, and relates to the technical field of network security situation awareness and analysis, and the platform comprises a multi-source data collection module which integrates flow, logs, assets and threat intelligence data, and carries out encryption transmission and standardization; the data preprocessing module purifies and optimizes data, and guarantees data quality and sensitive information security; the AI situation awareness analysis module extracts features through a deep learning model, dynamically evaluates the situation and identifies threats; the threat early warning and decision-making module triggers graded early warning and generates a targeted emergency response scheme; the visual display and interaction module displays information in multiple dimensions and supports query and report generation; and the data storage and tracing module adopts a mixed storage architecture, so that the data security and traceability are ensured. The platform integrates multi-source data and realizes situation accurate perception and intelligent decision by means of an AI technology; the early warning is accurate, the visual interaction is convenient, and the intelligent and efficient level of network security protection is comprehensively improved.
Owner:HUNAN CONGMAO TECH CO LTD

Network security situation awareness method and system and computer equipment

The invention provides a network security situation awareness method and system and computer equipment, and belongs to the technical field of network security. The method comprises the following steps: collecting and standardizing multi-source heterogeneous security data; constructing and dynamically updating a network asset and vulnerability knowledge graph; performing tactical labeling on the security event based on tactical, technology and process behavior model libraries to form a current attack context state; mapping the current state into a knowledge graph to deduce a potential subsequent attack path; performing quantitative risk assessment on the path, and calculating an initiation probability and a potential risk value; outputting situation awareness information containing the path and the probability and risk value thereof; and dynamically determining a key area needing to be updated preferentially in the knowledge graph according to an evaluation result, and triggering incremental updating. According to the method, the crossing from static monitoring to dynamic prediction is realized, the attack path can be actively deduced, quantitative risk assessment is carried out, meanwhile, the real-time performance of the knowledge graph is guaranteed through a focusing updating mechanism, and the initiative and accuracy of network security protection are improved.
Owner:SICHUAN RUIFANGDA TECHNOLOGY CO LTD

Network security situation awareness prediction method and device based on knowledge graph

The invention relates to the technical field of network security, in particular to a network security situation awareness prediction method and device based on a knowledge graph, and the method comprises the steps: integrating a network topological structure, asset importance, security defects and traffic mode information, and generating a network basic state graph containing initial nodes and edges; according to the application, a knowledge graph structure is constructed on the basis of a network topology structure, and then multi-modal information such as network asset importance, security defects and traffic modes is incorporated to form a network basic state graph model; further, the basic state map model is mapped into a network attack path map structure based on a network attack inherent mode, a probability model is introduced, the security situation of nodes in the network is quantitatively calculated, and a network security situation static map is formed; and finally, carrying out quantitative prediction on high-risk nodes, high-risk attack paths and the overall situation of network security in the network.
Owner:BEIJING ACT TECH DEV CO LTD +1

Network security situation awareness system based on federated learning driving

The invention discloses a network security situation awareness system based on federated learning driving, and relates to the technical field of distributed computing. The visual management center is in communication connection with a data acquisition module, a distributed federation learning module, a virtual storage management module, a security policy analysis module and an automatic response processing module, and all the modules are in electric signal connection. Through the federated learning technology, the security situation awareness model is locally trained on the multiple distributed nodes, centralized storage and transmission of data are avoided, the risk problem of data privacy leakage in a traditional network security situation awareness system is effectively solved, each node only processes and analyzes data locally, data uploading is not needed, and the network security situation awareness system is convenient to use. Therefore, on the premise of ensuring data security and privacy, cross-node knowledge sharing and model optimization are realized, and the data privacy protection capability of the system is greatly improved.
Owner:BAODING GUANGYUTONG NETWORK TECHNOLOGY CO LTD

Knowledge graph optimization method and device suitable for network security situation awareness data

The invention relates to the technical field of knowledge graph optimization, in particular to a knowledge graph optimization method and device suitable for network security situation awareness data. The method comprises the following steps: constructing an initial knowledge graph; obtaining an importance degree sequence of the entity category and an importance degree score of each relation category; based on the importance degree sequence of the entity categories, sequentially dividing the entity features in each entity category according to the importance degree from low to high, and obtaining a core entity feature sequence, a key entity feature sequence and an edge entity feature sequence; obtaining a rejected entity feature set; obtaining a rejection relationship category set; deleting triads with entity features in the entity feature set and relation categories in the relation category set from the initial knowledge graph, and obtaining optimized triads; and reconstructing the initial knowledge graph based on the optimized triple. According to the method, the knowledge graph can be optimized well.
Owner:STATE GRID ANHUI ELECTRIC POWER CO LTD

Knowledge graph construction method and device for network security situation awareness

The invention relates to the technical field of knowledge maps, in particular to a knowledge map construction method and device for network security situation awareness. The method comprises the following steps: constructing a plurality of triads; constructing an initial knowledge graph based on the plurality of triads; on the basis of entity category labels, sorting entity categories in the initial knowledge graph according to importance degrees; on the basis of the entity category labels and the relationship category labels, sorting the relationship categories in the initial knowledge graph according to importance degrees, and obtaining an importance degree score of each relationship category; on the basis of the importance order of the entity categories and the importance score of each relationship category, optimizing triples in the initial knowledge graph; and completing the construction of the knowledge graph based on the optimized triple. According to the method, the redundant data and the weak association data in the knowledge graph of the network security situation awareness data can be better eliminated.
Owner:STATE GRID ANHUI ELECTRIC POWER CO LTD

Network security situation awareness prediction system and method based on large model

The invention relates to the technical field of network security, and particularly discloses a network security situation awareness prediction system and method based on a large model, and the method comprises the steps: carrying out the cleaning analysis and key field extraction of a network security log to generate a structured event stream, carrying out the modal characterization processing to extract the deep semantic feature representation of the structured event stream, and carrying out the modal characterization processing; and meanwhile, time sequence modeling is performed on the network flow data, and a time sequence characteristic mode of the network flow is learned. Then, a cross-modal semantic alignment technology is adopted to realize feature dimension alignment on network security log semantic features and network traffic time sequence features, and fine-grained feature transfer interactive reasoning is performed on the network security log semantic features and the network traffic time sequence features to deeply mine potential association and cooperative behavior modes between the network traffic and log events; and the specific stage of the attack behavior is predicted by using the multi-mode large model subjected to field fine tuning. According to the method, the attack behavior track can be accurately captured by fully utilizing complementary information among heterogeneous data, and the accuracy and foresight of situation awareness are improved.
Owner:STATE GRID HENAN INFORMATION & TELECOMM CO +1

Network security situation awareness method based on artificial intelligence

The invention discloses a network security situation awareness method based on artificial intelligence, and the method comprises the following steps: collecting multi-source heterogeneous data, and generating a standardized data set; spatial-temporal feature decoupling is carried out, and spatial-temporal dimension features are separated; fusing the time-space cross attention, and outputting a fused time-space feature vector; constructing a causal inference engine, and outputting a dynamic causal graph and an anti-fact inference result set; constructing a dynamic risk propagation model, and outputting a whole asset risk value matrix and a risk propagation path diagram; generating a situation quantization matrix, constructing an adversarial training decision network, and outputting a defense strategy set verified by adversarial training; automatically generating a strategy; and a man-machine cooperative verification closed loop is realized. According to the method, dynamic reconstruction of a threat propagation path is realized through spatial-temporal feature decoupling and a causal reasoning engine, and a risk positioning error is reduced; and the adversarial training decision network is combined, so that the misjudgment rate of the defense strategy in the simulation APT attack test is reduced.
Owner:BEIJING BEILONG YUNHAI NETWORK DATA TECH CO LTD

Network security situation awareness method and system based on large model and threat assessment

The invention provides a network security situation awareness method and system based on a large model and threat assessment, and relates to the technical field of network security intelligence, and the method comprises the steps: collecting situation environment data of current network security, inputting the data into a fine tuning situation awareness large model for analysis and judgment, and obtaining a situation reasoning result; extracting threat assessment parameters from the situation environment data to obtain a situation assessment result; and performing consistency comparison on the situation inference result and the situation assessment result, and outputting a situation awareness result of the current network security. According to the method, the problems of limited sensing granularity, high rule maintenance cost and difficulty in multi-source data fusion in the existing network security protection method are effectively solved.
Owner:WUHAN SHIP COMM RES INST (NO 722 RES INST OF CHINA STATE SHIPBUILDING CORP) +1

Network security situation awareness method and system

The invention relates to the technical field of network security monitoring, and discloses a network security situation awareness method and system, and the method comprises the steps: collecting a multi-source heterogeneous log, carrying out the standardized analysis, and obtaining log event data; performing real-time analysis by utilizing a dynamic baseline association engine based on the log event data to obtain log association alarm data, analyzing a triple from the log association alarm data, constructing a basic knowledge graph based on the triple, performing rule reasoning and embedded reasoning, and integrating reasoning results to form a situation-enhanced security situation knowledge graph; threat data are extracted according to the security situation knowledge graph, the threat data are optimized in combination with a graph neural network GAT to obtain a final network attack threat value, network security situation awareness is carried out based on the network attack threat value, and the threat data comprise comprehensive criticality and an attack influence range. According to the invention, the efficiency and effect of network security management can be improved.
Owner:TONGFANG KNOWLEDGE DIGITAL PUBLISHING TECH CO LTD

Network security situation awareness method and system based on big data analysis

The invention relates to a network security situation awareness method and system based on big data analysis, and belongs to the technical field of network security. The method comprises the steps of collecting original network data which comprises original network data flow and original protocol data in broadband service, training a network security situation awareness model based on a preset network security situation awareness standard set, the network security situation awareness model comprises a network flow analysis model and a protocol analysis model, generating a network state label through the network security situation awareness model, and evaluating a network security level through a rating rule according to the network state label. And outputting a network security situation awareness instruction through an instruction control script according to the network security level, generating a network security situation report through an automatic reporting tool according to the original network data, the network state label and the network security level, and displaying the network security situation report through a data visualization tool.
Owner:SHANGHAI FOUR-LEAF CRUCI INFORMATION TECHNOLOGY CO LTD

Network security situation awareness method based on artificial intelligence

The invention provides a network security situation awareness method based on artificial intelligence, and relates to the technical field of network security. Real-time monitoring and multi-source data fusion analysis are performed on a network communication behavior, a host operation state, threat alarm information and a relationship between vulnerabilities and a topological structure; constructing a threat intensity parameter, a behavior anomaly rate parameter, a vulnerability exposure degree parameter and a traffic anomaly density parameter, and calculating a risk potential energy index to realize quantitative evaluation of a network risk state; introducing an attack chain dynamic coupling index to perform dynamic analysis on a multi-stage attack evolution trend, and judging an attack chain formation risk; depicting an abnormal flow distribution concentration degree through a risk propagation convergence entropy index, and identifying concentrated penetration and critical path breakthrough risks; and defense strategies such as risk tracing, attack chain blocking and key path reinforcing are given, so that accurate recognition, trend prediction and adaptive defense of complex network attacks are realized.
Owner:CHENGDU RUIDIOU TECH CO LTD

Remote sensing satellite network security situation awareness method and system with dual prevention mechanisms

The invention discloses a remote sensing satellite network security situation awareness method and system with dual prevention mechanisms, and the method comprises the steps: obtaining multi-source heterogeneous data from a remote sensing satellite ground system network, and generating a structured data set through cleaning, denoising and standardization processing; and according to the structured data set, recording network assets by adopting an asset identification algorithm, and generating a risk thermodynamic diagram of the network assets through a Bayesian network model and an entropy weight method. And according to the risk thermodynamic diagram and the structured data set, adopting a deep learning model to detect abnormal traffic and behaviors, and generating a hidden danger list marked with priorities through a general vulnerability scoring standard and a threat intelligence library. And according to the risk thermodynamic diagram and the hidden danger list, constructing a dynamic security situation map by adopting a graph database and a community discovery algorithm. Therefore, the real-time fusion capability of multi-source heterogeneous data is improved, a dynamic attack chain reasoning mechanism is enhanced, and collaborative decision-making of risk early warning and hidden danger treatment is realized.
Owner:NAT SATELLITE METEOROLOGICAL CENT

Network security situation awareness method based on Transform and time sequence prediction

The invention belongs to the technical field of network security, and discloses a Transform and time sequence prediction-based network security situation awareness method, which comprises the following steps of: performing multi-level feature engineering on traffic data subjected to quality monitoring, and extracting three layers of 78-dimensional features; a situation assessment model based on Transform is constructed, and continuous situation scores are output through association between multi-head self-attention learning features; the continuous situation scores are aggregated according to a time window to form a situation score sequence, and a future situation is predicted by a mixed architecture of a Transform encoder and an LSTM decoder, so that coupling cooperation of evaluation and prediction is realized. According to the method, the real-time performance is guaranteed, meanwhile, good engineering practicability is achieved, and the flow record is converted into the situation scoring sequence with remarkable autocorrelation through window aggregation, so that the short-time prediction stability and learnability are improved.
Owner:NANJING UNIV OF POSTS & TELECOMM

Intrusion situation prediction method based on SEA-DDQN adaptive reinforcement learning

The invention belongs to the technical field of network security situation awareness, and discloses an intrusion situation prediction method based on SEA-DDQN adaptive reinforcement learning, and the method comprises the following steps: obtaining a network flow data set; preprocessing the obtained network flow data set to obtain a standardized data set; and constructing a deep attention Q network SEA-DDQN model based on double values, and carrying out network security intrusion situation prediction ISP to realize an ISP process. According to the intrusion situation prediction method based on SEA-DDQN adaptive reinforcement learning, through continuous interaction with a traffic environment, the prediction capability is continuously improved, so that the model can flexibly cope with complex and continuously changing threat scenes; the SEA-DDQN uses the advantages of reinforcement learning to optimize the adaptivity and decision making process of the model, thereby enhancing the anti-interference capability of the model in a dynamic environment.
Owner:CHENGDU UNIV OF INFORMATION TECH

Network security situation awareness method and system based on multi-dimensional data fusion

The invention relates to the technical field of network security, and discloses a network security situation awareness method and system based on multidimensional data fusion, and the method comprises the steps: 1, collecting network behavior data from at least two different data sources; 2, cleaning and formatting the network behavior data; 3, a security situation score is calculated by adopting a formula # imgabs0 #, S is the security situation score, wi is the weight of the ith dimension, and Di is the data value of the network behavior data of the corresponding dimension; and 4, predicting potential security threats according to the security situation scores. The system corresponds to the method. According to the invention, comprehensive monitoring and accurate early warning of the network security state can be realized.
Owner:GUANGDONG POWER GRID CO LTD +1

Photovoltaic power station network security situation awareness and early warning method and system

The invention relates to the technical field of network security situation awareness and early warning, and discloses a photovoltaic power station network security situation awareness and early warning method and system, and the method comprises the steps: carrying out the multi-source heterogeneous data collection of a photovoltaic power station and a social network, and carrying out the distributed preprocessing and feature extraction of the collected data, carrying out weighted fusion analysis on the comprehensive feature data through a situation awareness model, predicting potential attacks through an attack prediction model, calculating a network security situation in real time through a deep belief network, and carrying out automatic attack blocking by a centralized control center and a plant station operation and maintenance terminal; encryption protection is carried out through a forward isolation device and a VPDN tunnel technology. According to the invention, situation awareness and risk prediction are carried out through a deep learning algorithm, automatic attack blocking and headquarters-plant-station intensive management and control are realized in combination with a dynamic early warning mechanism, a trapping system and a block chain technology, and the monitoring, early warning and protection capabilities of the network security of the photovoltaic power station are significantly improved.
Owner:DATANG KUNYU CLEAN ENERGY CO LTD +1

Network security situation awareness method and system based on deep learning

The invention discloses a network security situation awareness method and system based on deep learning, and the method comprises the steps: generating a time-space sequence data set through integrating a multi-source flow log and a behavior record, extracting the abnormal signal intensity, and generating an embedded vector set representing attack multidimensional through employing a graph representation learning method; and when the abnormal signal intensity exceeds a threshold value, mining time sequence relevance through a sequence analysis model, judging a hidden threat evolution path, updating complex attack chain representation in real time by utilizing a dynamic tracking mechanism, generating future threat probability distribution by fusing a risk prediction method, and determining a high-risk threat priority sequence. For high-risk threats, an early warning mechanism is activated through infrastructure influence assessment, a safety guarantee protocol is integrated, a protection layer is applied, and enhanced network defense configuration is generated. According to the embodiment, through integration of spatio-temporal data fusion, dynamic threat tracking and risk prediction, the detection precision and response speed of hidden threats are remarkably improved, and the safety of key infrastructures is guaranteed.
Owner:HUNAN JIEYIXIN TECH CO LTD

Unknown attack detection method and system for intelligent network security situation awareness

The invention discloses an unknown attack detection method and system for intelligent network security situation awareness, and the method comprises the steps: obtaining multi-dimensional data of a power grid monitoring system, carrying out the data preprocessing, carrying out the network attack preliminary detection of the multi-dimensional data through a pre-built network security situation awareness framework, and outputting suspected attack data, the method comprises the steps of performing data training on historical attack data through an improved OCN open set classification network, identifying attack features of each known attack type, performing semantic similarity calculation on the attack features and suspected attack data, performing attack feature mapping and clustering on the suspected attack data based on semantic similarity, and obtaining an unknown attack feature clustering result. And according to the unknown attack clustering result, carrying out attack type classification on unknown attacks in the suspected attack data to obtain an unknown attack detection result. The method has the effects of detecting unknown attack means in time, effectively reducing the risk that the power grid system suffers from network attacks and guaranteeing safe and stable operation of the power grid system.
Owner:CHINA DATANG CORPORATION SCIENCE AND TECHNOLOGY GENERAL RESEARCH INSTITUTE +1

Network security situation awareness method based on artificial intelligence

The invention relates to the technical field of network security, in particular to a network security situation awareness method based on artificial intelligence, which comprises the following steps: deploying probes on a plurality of key link nodes of a network, and acquiring a specific type of network basic maintenance message flowing through the node; based on the obtained message, microcosmic time sequence characteristics of the message are extracted, and a first time sequence signal is formed; comparing the first time sequence signal with a pre-stored node reference time sequence signal, executing collaborative deviation calculation, and generating a collaborative deviation coefficient; and based on the collaborative deviation coefficient, determining a local vibration intensity value of the node, converging local vibration intensity values of a plurality of nodes in the network, and executing spatial correlation fusion calculation. According to the method, anomaly detection is realized by analyzing the time sequence coordination rule of the network basic maintenance message, any abnormal condition damaging a normal coordination mode can be captured, and the recognition rate of unknown threats is improved.
Owner:NANJING KUNJIN NETWORK TECH CO LTD

Network security situation awareness and automatic response decision-making system based on AI

The invention discloses a network security situation awareness and automatic response decision-making system based on AI, and the system comprises a multi-source data processing module which is used for collecting multi-source data, executing time synchronization, field standardization and feature extraction, and generating a security event vector sequence; the situation modeling module is used for one-dimensional mapping and cross-source combination to form a situation representation vector; the attack relation modeling module is used for constructing a behavior combination structure and generating attack chain stage probability distribution and path contribution degree; the trend prediction module is used for extracting continuous time slices and inputting a time sequence modeling structure to generate a risk trend prediction result; the response strategy generation module is used for generating an optimal response action; and the closed-loop updating module is used for executing actions and updating parameters of each modeling module according to feedback information. According to the method, the multi-source security events are uniformly modeled based on the KAN network, so that collaborative updating of attack relation depiction, risk prediction and response generation is realized.
Owner:WUHAN DONGHU UNIV

Network defense system vulnerability simulation method based on generative adversarial network

The invention discloses a network defense system vulnerability simulation method based on a generative adversarial network. The method comprises the following steps: S1, generating a network security situation awareness data set; s2, obtaining a weighted attack path graph; s3, performing graph semantic coding on the weighted attack path graph, and mapping a condition vector set; s4, obtaining a converged candidate weak point configuration set; s5, generating a target weak point configuration list; s6, forming a weak bait cluster; and S7, collecting a detection behavior log aiming at the weak bait cluster in real time, generating an attacker interaction behavior data set by utilizing the behavior log and the transverse movement behavior log, updating a weighted attack path graph and a condition vector set based on the attacker interaction behavior data set, and performing online fine adjustment on the condition generative adversarial network to obtain a weighted attack path graph. And the step S5 and the step S6 are executed again. According to the invention, through comprehensive discrimination and constraint optimization, unification of high trapping value and low business risk is realized.
Owner:BEIJING RUISJINDA TECH CO LTD

Network security situation awareness and emergency response platform based on digital twinning

The invention discloses a network security situation awareness and emergency response platform based on digital twinning, which belongs to the technical field of network detection and comprises a data acquisition module for acquiring original data information related to network security; the data fusion and digital twinning modeling module is used for preprocessing the original data information, constructing a digital twinning virtual model and synchronously reflecting the processed data on the digital virtual model; the situation awareness analysis module is used for performing analysis based on the data in the virtual model environment so as to detect the network security state; and the response module performs corresponding emergency response based on the judgment result. According to the method, comprehensive analysis can be carried out by combining multiple pieces of data under the same influence layer to improve the detection accuracy, fusion analysis can be carried out by combining the data among multiple influence layers, the network security condition is judged according to the relevance among the influence layers, and the detection accuracy is further improved.
Owner:广东宜通衡睿科技有限公司

Network security situation awareness method and system based on large model and threat assessment

The invention relates to the technical field of network security, in particular to a network security situation awareness method and system based on a large model and threat assessment. The method comprises the following steps: firstly, acquiring and standardizing multi-modal security data in a cloud service environment in real time, distributing a behavior modal cluster for security event metadata through clustering analysis, and generating a security feature vector containing business semantics and behavior dynamic features based on a cluster center relocation technology; then constructing a local situation map reflecting asset topology and an access link by using a cloud security association model; semantic reasoning is performed on the atlas through a large language model, an attack intention is recognized, and an attack path is predicted; and finally, combining the path probability, the asset value and the vulnerability feature to quantitatively calculate a risk index, and automatically generating a response strategy. Semantic compression of massive logs is realized through modal clustering, and the calculation bottleneck of processing original data by a large model is overcome; and in combination with graph correlation and large model reasoning, the crossing from passive warning to active intention prediction is realized.
Owner:BEIJING ZHONGCHUANG HAISHENG TECHNOLOGY CO LTD

Computer network security situation analysis method and device and electronic equipment

The invention relates to the technical field of network security, in particular to a computer network security situation analysis method and device and electronic equipment, and the method comprises the following steps: S1, collecting small attack behavior data of abnormal small-scale data packet transmission, port scanning behavior and long-time session; s2, carrying out aggregation processing on the data collected in the S1, and generating a cumulative effect graph; s3, constructing a cumulative effect recognition model for outputting risk values of potential security threats in the network; s4, calculating the threat level of each network node; s5, dynamically adjusting a preset safety threshold; and S6, when the threat level exceeds the dynamically adjusted safety threshold, automatically generating a corresponding protection strategy. According to the method, cumulative effect identification of tiny attack behaviors is realized through the dynamic aggregation algorithm and the isolated forest algorithm, and the security threshold is adaptively adjusted and the protection strategy is generated in combination with the reinforcement learning algorithm, so that the accuracy of network security situation awareness and the timeliness of protection are improved.
Owner:SHENZHEN ANRUIZE TECH CO LTD

Information security comprehensive protection system of production enterprise

The invention discloses a production enterprise-oriented information security comprehensive protection system, which comprises a unified security management center, a region boundary protection module, a security computing environment module, a data full life cycle protection module, an authority management module, a threat active defense module and a network security situation awareness module, original dispersed and isolated safety capabilities are integrated into a linkage system through an integrated architecture of a unified safety management center and six functional modules through a unified interface / event bus, so that instant isolation and authentication of a transverse production control area, a management information area and a longitudinal remote operation and maintenance channel are realized, and the transverse penetration blocking rate is remarkably improved; role isolation and dynamic authorization are realized through the authority management module, the attack surface of a supply chain is greatly narrowed, the manual operation and maintenance workload is reduced by about six percent, and the overall safety toughness and operation efficiency of an enterprise are remarkably improved.
Owner:HENGTONG PRECISION COPPER FOIL TECHNOLOGY (DEYANG) CO LTD