Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

17 results about "Network security situation awareness" patented technology

A centralized control station network security situation awareness method and system

This application proposes a method and system for network security situation awareness at a centralized control station, belonging to the field of network security communication technology. The method includes: acquiring multi-source operational datasets corresponding to each sensing node in the centralized control station's sensing node set; extracting multi-dimensional feature vectors from each sensing node and performing feature offset analysis to obtain multi-dimensional offset feature vectors; calculating the degree of newness index of each sensing node; classifying the sensing node set into multiple levels by analyzing the degree of newness index to obtain multi-level sensing layers; constructing corresponding multi-level attack behavior detection models; and calling the multi-level attack behavior detection models to perform attack behavior risk detection on sensing nodes belonging to each level of sensing layer. By adaptively hierarchically modeling based on the degree of newness of sensing nodes, targeted attack behavior detection strategies are adopted for sensing nodes with different degrees of newness, thereby improving the accuracy and timeliness of network security situation awareness at the centralized control station in scenarios of dynamic node expansion.
Owner:BEIJING KEDONG ELECTRIC POWER CONTROL SYST CO LTD +2

A method and device for network security situation awareness

This application relates to the field of network situational awareness technology, and discloses a method and device for network security situational awareness. The method includes: identifying regulatory entities and collecting abnormal events; identifying interactive and operational behaviors as risk characteristics; constructing a first risk identification model and deploying it on an edge terminal; collecting the type and sensitivity attributes of the regulatory entities; dynamically forming regulatory assistance pairs based on the attributes; generating a second risk identification model by weighted averaging of the parameters of the first model based on the regulatory assistance pairs and deploying it in the cloud; real-time interactive data is preferentially screened by the cloud-based second model; if a risk is identified, a structured report is generated and distributed; if not identified, it is reviewed by the first model at the edge terminal. This application achieves distributed intelligent perception with cross-domain collaboration and data not leaving the domain, solving the model bias and centralized delay problems caused by insufficient samples of a single entity, and significantly improving detection accuracy, response efficiency, and collaborative defense capabilities in low-sample scenarios.
Owner:STATE GRID BEIJING ELECTRIC POWER CO

A Deep Learning-Based Network Security Situation Awareness Method and System

PendingCN122316711AData packArea network
This invention discloses a network security situation awareness method and system based on deep learning, relating to the field of deep learning technology. The method includes deploying a network security data acquisition component within a regional network to collect and parse network data packets, generating security event data; constructing a communication graph of network communication relationships based on the security event data, and embedding and mapping the communication edge features in the communication graph to generate communication edge embedding vectors as a vectorized representation of communication relationships; performing topology encoding based on the communication graph to generate position codes, and fusing the communication edge embedding vectors with the position codes to form fused edge vectors containing network topology information; introducing a multi-head attention mechanism to update the fused edge vectors to obtain the final edge vectors. This invention can not only more accurately identify and distinguish different types of attack behaviors, but also significantly improve the accuracy of network security status perception.
Owner:FUJIAN HUADIAN KEMEN POWER GENERATION CO LTD

Network security situation awareness method and system for signal creation environment

PendingCN122339805AIt innovationAttack
This invention relates to the field of network security technology, specifically to a network security situation awareness method and system for the domestic IT innovation environment. The method includes: extracting attack sub-links from a directed graph of entity relationships based on entity log data across different time periods; assigning risk indicators to each entity based on the attack sub-links; selecting predicted complete links for each attack sub-link; assigning association relationships to different attack sub-links based on the attack sub-links traversed by all predicted complete links, and determining the complete attack link accordingly; updating the entity's risk indicators based on the obtained complete attack links, and re-acquiring a more accurate complete attack link. This invention can intelligently associate and iteratively optimize attack fragments across time periods, effectively reconstructing the attacker's complete intent and improving the accuracy and reliability of situation awareness in the complex domestic IT innovation environment.
Owner:BEIJING GUANGYIN JIAYE TECHNOLOGY CO LTD

Energy private network security situation awareness method and system fusing internet of things and artificial intelligence

This application discloses a method and system for network security situation awareness of a private energy network integrating the Internet of Things (IoT) and artificial intelligence. The method includes: extracting frequency fluctuation feature sequences and communication interaction data based on the energy network's operating frequency signal and the network communication data stream; constructing a unified frequency-time reference axis for the entire network, mapping the communication interaction data to the frequency-time reference axis, and generating a frequency-anchored data sequence; performing semantic parsing on the energy network protocol messages in the communication interaction data, constructing a semantic representation of control commands and their expected physical effects model; performing semantic-temporal consistency verification to obtain semantic-physical coupling residuals; calculating the temporal reliability score of the communication data and identifying abnormal control behaviors; inputting the temporal reliability score and abnormal control behaviors into a preset situation assessment model, and outputting the network security situation value of the private energy network. This application improves the accuracy of network security situation detection.
Owner:GUIZHOU INST OF COAL SCI +1

Artificial intelligence based cyber security situation awareness method and system

PendingCN122348853AStream dataEngineering
The application provides an artificial intelligence-based network security situation awareness method and system. By acquiring and processing network security awareness flow data sequences, the starting and ending of threat mode events are located, the target events of intrusion activities in each network security awareness flow data are located, the boundary nodes of threat mode events are determined by calculating the connection degree between the network security situation vector sets corresponding to these target events, and the events where the intrusion migration nodes and intrusion persistence nodes are located are accurately identified according to the boundary nodes for each network security awareness flow data. Through in-depth analysis of the intrusion migration characteristics and the intrusion persistence characteristics of these events, accurate intrusion migration nodes and intrusion persistence nodes are generated. Finally, based on the comprehensive information of the intrusion migration nodes and the intrusion persistence nodes, the intrusion activities in each network security awareness flow data are determined, and the comprehensive and real-time awareness of the network security situation is realized.
Owner:WUHAN ZHONGYUN INTERNET TECH CO LTD

Digital mine network security situation awareness method and system

The invention belongs to the technical field of industrial internet security, and particularly relates to a digital mine network security situation awareness method and system, and the method comprises the following steps: S1, accessing the network flow of a mine industrial switch, deconstructing a data packet into an instruction domain, an address domain and a load domain through protocol analysis, and extracting a timestamp and the binary content of each domain; s2, calculating the Shannon entropy of the protocol field in the current time window, and calculating the abnormal entropy increase index of the protocol field according to the average entropy value and the standard deviation under the historical normal working condition, thereby evaluating the hidden channel risk; and S3, extracting physical values in the continuous data packets, and calculating a physical inertia conflict coefficient according to the maximum change rate allowed by the physical parameters of the equipment. According to the method, the physical law is introduced as a safety criterion, so that the false alarm rate is effectively reduced, and precise perception of advanced persistent threats is realized.
Owner:CHINA ELECTRIC CLOUD INFORMATION TECH CO LTD

A method and system for network security situation awareness based on honeycomb drive

ActiveCN122027363BPathPingPropagation delay
The application provides a network security situation awareness method and system driven by a honeynet, and relates to the technical field of network security management.The method provided by the application comprises the following steps: receiving threat event reporting from a honeynet trapping node, extracting an attacker behavior path, session content and triggering features, and performing first attack path correction according to the node's own topology position and attack flow information; when there are multiple honeynet trapping nodes simultaneously capturing events from the same attack source, the propagation delay and path deviation of the attack chain in the network are calculated through time synchronization and event matching between the honeynet trapping nodes, the attack situation is adjusted in real time, and the projection error of the attack propagation path in the network topology is corrected. The perception system realizes the collaborative work of distributed trapping nodes by introducing a honeynet driving mechanism, calculates the propagation delay and path deviation of the attack chain through time synchronization and event matching, and greatly improves the spatial accuracy of threat positioning.
Owner:INFORMATION & COMMNUNICATION BRANCH STATE GRID JIANGXI ELECTRIC POWER CO +1

A network security situation awareness method, device and electronic equipment for an open-pit mine scene

The present application provides an open-pit mine network security situation awareness method, device and electronic equipment, relating to the technical field of network security. In view of the particularity of the open-pit mine network, combined with its characteristics such as multiple mobile nodes, complex industrial protocols and harsh physical environment, through multi-dimensional data fusion, dynamic clustering optimization, cross-modal large model reasoning and industrial honeypot trapping, etc. The present application realizes accurate perception and prediction of the open-pit mine network security situation. The present application reduces the dimension of open-pit mine network security situation awareness, improves the perception efficiency and accuracy in complex environment, and provides a strong guarantee for the safety of open-pit mine key infrastructure.
Owner:LIAONING TECHNICAL UNIVERSITY

Big data based cyber security situation awareness method and system

PendingCN122372325APathPingData stream
The present application relates to the technical field of big data, and particularly relates to a network security situation awareness method and system based on big data, which comprises the following steps: decomposing a multi-source heterogeneous security event data stream into behavior primitives, analyzing a combination mode and a dependency relationship to reconstruct an attack mode structure, inferring an attack target and calculating a confidence degree based on a behavior primitive sequence, calculating an attack path cost benefit ratio according to resource consumption and availability of an unexecuted node, analyzing node centrality and necessity to identify a key node and quantify an exposure degree, and integrating inference results, cost benefit distribution and exposure degree to generate a network security situation awareness result, so that comprehensive awareness and accurate prediction of network attacks are realized, and the accuracy and efficiency of situation awareness are improved.
Owner:BEIJING HEYUAN TECHNOLOGY CO LTD

A power monitoring system information network security protection method based on situation awareness

The application provides a power monitoring system information network security protection method based on situation awareness, and relates to the technical field of power plant network security, which comprises the following steps: collecting data that has an influence on the network security of a power plant, obtaining a network security data set of the power plant, and performing pretreatment; constructing a deep learning model based on a convolutional neural network model and a long short-term memory network model; optimizing the loss function of the deep learning model; training the model using the pretreated network security data set of the power plant to obtain a power plant network security situation awareness model; setting quantum attack-resistant identity-based encryption parameters; collecting real-time data of the power plant, and performing encryption and decryption using the quantum attack-resistant identity-based encryption parameters during the transmission of the real-time data of the power plant; and inputting the decrypted real-time data of the power plant into the model to monitor the current network security status of the power plant. The application can realize intelligent power plant network security situation awareness and power plant network security status monitoring.
Owner:SOUTHWEST ELECTRIC POWER DESIGN INST OF CHINA POWER ENG CONSULTING GROUP CORP

Multi-dimensional network security situation awareness system and method for big data

This invention discloses a multi-dimensional network security situation awareness system and method for big data, specifically relating to the field of network security technology for big data. It includes a multi-source data acquisition module for collecting raw datasets; a data preprocessing and fusion module for preprocessing and fusing the raw data to form a structured dataset; a feature construction and correlation analysis module for extracting relevant features from the structured dataset and outputting multi-dimensional feature vectors; a dynamic pattern recognition and state assessment module for identifying data patterns based on the multi-dimensional feature vectors using a collaborative fusion mechanism of adaptive clustering and pattern recognition algorithms, calculating a comprehensive state index, and outputting data pattern assessment results; and an execution feedback module for generating data application instructions and business instructions. This invention achieves deep integration of multi-source data and accurate situation assessment, effectively improving the comprehensiveness, accuracy, and real-time performance of network security situation awareness in a big data environment.
Owner:泗水县大数据中心(泗水县电子政务中心) +1

A deep learning-based network security situation awareness system and method

PendingCN122457340ARealize the structureImplement multi-dimensional annotationAttackEngineering
The application discloses a network security situation awareness system and method based on deep learning, comprising the following steps: collecting and processing multi-source heterogeneous network security data in a target network security scene; constructing an event semantic unit set and an event semantic coupling relationship set; performing constraint filtering and attack chain fragment arrangement processing on discrete security events; constructing a heterogeneous time sequence relationship topology and performing time sequence embedding coding and correlation fusion; extracting a behavior evolution sequence and mapping to an attack chain stage atlas; generating a network security situation representation vector set through an improved TGN model; identifying complex attack behaviors, confirming a propagation path and performing situation risk grading to generate a network security situation awareness result. The application fully utilizes a deep learning method, constructs a multi-source data attack chain analysis model, realizes network situation awareness, and has the advantages of high accuracy, strong risk prediction and timely response.
Owner:SHAANXI HUADIAN NEW ENERGY POWER GENERATION CO LTD

An intelligent decision optimization method and system for network security situation awareness

PendingCN122394929APathPingAttack
The application discloses an intelligent decision optimization method and system for network security situation awareness, relates to the technical field of intelligent decision optimization, and comprises the following steps: collecting log data, traffic data and security event data in a network, performing standardization processing on the collected data, and constructing a network state node set and a correlation between nodes based on the standardized data; based on the network state node set, a recursive component with a unique entrance and exit is constructed, a calling relationship and a return path are generated between the recursive components, a hierarchical recursive attack path structure is formed, a risk value is set for each node in the recursive attack path structure, and the risk value is propagated layer by layer forward according to the correlation, so that a global network security situation result is obtained; and the application changes network security protection from passive response to active optimization, and significantly improves intelligent decision capability and overall protection effect.
Owner:FUJIAN HUADIAN KEMEN POWER GENERATION CO LTD

A multi-source cross-domain network security big data fusion management and collaborative service method

This invention discloses a method for multi-source, cross-domain cybersecurity big data fusion governance and collaborative services, comprising the following steps: A: acquiring standardized multi-source heterogeneous data; B: performing security entity identification and semantic modeling on key objects in the standardized multi-source heterogeneous data; C: constructing a graph and modeling behavioral paths based on the acquired set of triples; D: obtaining time-series behavioral sequences based on the security behavior graph, and using a predefined attack chain pattern library for attack chain identification and causal reasoning; E: conducting a comprehensive security risk assessment for each attack path based on a multi-factor weighted security risk model; F: generating a collaborative response strategy based on attack chain characteristics and a comprehensive security risk level. This invention can achieve comprehensive governance and intelligent collaborative services for cybersecurity data by fusing and governing heterogeneous security data from different security domains, thereby improving cybersecurity situational awareness and response capabilities.
Owner:SHANDONG UNIV +1