Patents
Literature
Patsnap Copilot is an intelligent assistant for R&D personnel, combined with Patent DNA, to facilitate innovative research.
Patsnap Copilot

134 results about "Network security situation awareness" patented technology

Attack-oriented network security situation prediction method, device and system

ActiveCN108494810ARealize dynamic associationIn line with the actual environmentData switching networksSecuring communicationCountermeasureAttack graph
The invention belongs to the technical field of network security and particularly relates to an attack-oriented network security situation prediction method, device and system. The method comprises the following steps: detecting and collecting alarm data and network environment operation and maintenance information in a network countermeasure environment, obtaining an element set required by network security situation prediction, wherein the element set comprises three types of information of an attacker, a defense party and a network environment; evaluating the attacker capability and the level of the defense party, establishing a dynamic Bayesian attack graph, and calculating an attack phase number and an attack state occurrence probability vector; and combining a vulnerability scoring standard and network asset information, and performing time-space dimension quantification on the network security situation value. According to the method, dynamic association of the situation elements of the defense party, the attacker, the environment information and the like is achieved, the actual environment of the network is better conformed to, the future situation and the attack occurrencetime can be accurately predicted, higher prediction efficiency is achieved, and storage scale and timeliness of network security situation awareness are optimized, so as to provide more effective guidance for network protection.
Owner:PLA STRATEGIC SUPPORT FORCE INFORMATION ENG UNIV PLA SSF IEU

Network security situation awareness system and method based on information correlation

The invention relates to a network security situation awareness system and method based on information correlation. The system comprises a data acquisition module, a network security situation evaluation module, a network security situation prediction module and a network situation visualization module, wherein the data acquisition module is used for acquiring network essential information; the network security situation evaluation module is used for quantitatively analyzing threat, frangibility and stability of the network by utilizing the network essential information, thereby analyzing the current network security situation; the network security situation prediction module is used for predicting the network security situation according to historical information and current state of the network security situation; and the network situation visualization module is used for visually displaying network security indexes according to the analysis and prediction result of the network security situation. The invention solves the problem that the existing network situation awareness system lacks data validity verification, data correlation and quantitative analysis, so that the network security situation awareness is more accurate.
Owner:INST OF COMPUTING TECH CHINESE ACAD OF SCI

Network security situation awareness system and method

InactiveCN110445807AImprove securityEasy to collect countermeasuresTransmissionTraffic capacitySecure state
The invention belongs to the technical field of network information security, and particularly relates to a network security situation awareness system and method. The system comprises a data acquisition unit used for acquiring network security elements such as security logs, system logs, vulnerability data and flow data in a network; a network security situation analysis unit which is used for processing and fusing the network security element data by means of classification, merging, correlation analysis and the like, and comprehensively analyzing fused information; a network security situation evaluation unit which is used for evaluating the security state of the current network according to the analysis result of the network security situation analysis unit; a network security situation prediction unit which is used for predicting the development trend of the network security state according to the security state and the historical information of the current network; a network security situation linkage unit which is used for handling security events according to the current network security state and the development trend of the current network security state; and a network security situation tracing unit which is used for positioning an attack source, discovering an attack path and obtaining evidence of an attack behavior.
Owner:瑞森网安(福建)信息科技有限公司

Power communication network security situation awareness and prediction method based on IRT hierarchical analysis and LSTM (Long Short Term Memory)

ActiveCN107786369AReflect security posturePrediction results are accurate and efficientData processing applicationsOther databases retrievalNetwork connectionImportance Weight
The invention discloses a power communication network security situation awareness and prediction method based on IRT hierarchical analysis and LSTM (Long Short Term Memory). The method is used for solving awareness and prediction on the security situation in the existing power communication network. The method comprises the implementation processes of: firstly, extracting characteristics influencing network security situation evaluation from network connection condition data acquired in the power communication network, furthermore, calculating a network security situation value based on a hierarchical IRT model, and then, establishing a network security situation prediction model based on LSTM, so that prediction on the security situation of the power communication network is realized. Byadoption of the method disclosed by the invention, the accuracy of the importance weight in a security situation evaluation process can be effectively improved; for the time sequence properties of anetwork security situation, the security situation of the power communication network can be predicted better; and furthermore, the network security condition can be reflected and predicted more accurately and effectively through the established model evaluation and prediction method.
Owner:POWER DISPATCHING CONTROL CENT OF GUANGDONG POWER GRID CO LTD

Method and device for perceiving network security situation and perceptual model training method and device

The invention discloses a method and device for perceiving a network security situation based on Tensorflow and Docker and a perceptual model training method and device. The perceptual model training method comprises the following steps: acquiring historical network situation element data; adopting the historical network situation element data to train a preset network security situation perceptual model, wherein the network security situation perceptual model comprises a Tensorflow width and depth learning submodel running in a Docker container; judging whether a training result of the network security situation perceptual model achieves the expectation; and when the training result of the network security situation perceptual model does not achieve the expectation, executing the step of acquiring the historical network situation element data to the step of adopting the historical network situation element data to train the preset network security situation perceptual model repeatedly until the training result of the network security situation perceptual model achieves the expectation. Therefore, massive network data can be processed efficiently, so that the network security situation can be perceived effectively.
Owner:GLOBAL ENERGY INTERCONNECTION RES INST CO LTD +2

Network security situation awareness model and method based on CE-RBF

The invention discloses a network security situation awareness model and method based on CE-RBF. The model comprises a data preprocessing module, a situation calculation module, a parameter optimization module and a situation prediction module. The method comprises the following steps: collecting data sets from different sources, and extracting principal component information for situation awareness to obtain asset attack threat data and system state data; calculating a risk value according to the asset attack threat data of the network equipment, and evaluating the security situation of the whole network; determining initial parameters of the RBF neural network, establishing an optimization objective function, optimizing the parameters in the optimization objective function by using a CEalgorithm, substituting the optimal parameter set into the RBF neural network after finding the optimal parameter set, and training by using historical network situation values as sample data; and performing situation prediction by using the trained RBF neural network. According to the method, the problem of parameter optimization in the high-dimensional model is solved by utilizing the efficientoptimization capability of CE, and the prediction capability of the neural network is improved.
Owner:湖北央中巨石信息技术有限公司

Operation risk assessment method and device based on network security situation awareness system

The invention discloses an operation risk assessment method and device based on a network security situation awareness system. The method comprises the steps: collecting historical data of the networksecurity situation awareness system in advance and analyzed; performing feature selection and data preprocessing on historical data of the network security situation awareness system to generate a training set and a test set for training a learning model; completing training of a learning model by adopting a machine learning algorithm, and exporting an intelligent analysis model after the learning model meets the average accuracy requirement; calculating expected recovery power supply time and loss load of the intelligent analysis model by adopting a general recovery target algorithm of the power system; and performing risk assessment calculation according to the expected power restoration time, the loss load and the threat intrusion probability of the intelligent analysis model to obtaina corresponding network security operation loss risk value. The method and device can combine the power system intrusion probability model and the network security situation awareness system to evaluate and calculate the operation risk, thus improving the risk evaluation accuracy.
Owner:CHINA ENERGY ENG GRP GUANGDONG ELECTRIC POWER DESIGN INST CO LTD

Distributed network situation awareness method and system, server and node equipment

InactiveCN111885040AImprove timelinessImprove perception and protection capabilitiesDigital data information retrievalResource allocationConcurrent computationAttack
The invention belongs to the technical field of network security, and particularly relates to a distributed network situation awareness method and system, a server and node equipment, and the method comprises the steps: carrying out the data fusion for a network node security data source through calling an HADOOP interface and employing a MapReduce model, and obtaining a security event in a current time period; performing network security situation assessment by quantizing security event threat risks; and predicting the security situation according to the attack stage identified in the quantization process in combination with the network attack graph to obtain an attack intention. .Calculation and storage needing huge computing power in the system are expanded to each node in the HADOOP cluster, operation and processing are performed by utilizing the parallel computing and storage capacity of the cluster, parallel computing is realized by utilizing MapReduce, distributed network security situation awareness oriented to large-scale data can be realized The network security situation awareness storage scale and timeliness are optimized, and the awareness protection capability for hidden, cooperative, large-scale and multi-stage attacks such as APT attacks is improved.
Owner:PLA STRATEGIC SUPPORT FORCE INFORMATION ENG UNIV PLA SSF IEU +1
Who we serve
  • R&D Engineer
  • R&D Manager
  • IP Professional
Why Eureka
  • Industry Leading Data Capabilities
  • Powerful AI technology
  • Patent DNA Extraction
Social media
Try Eureka
PatSnap group products