Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

57 results about "Network security situation awareness" patented technology

Network security situation awareness and analysis platform based on AI

The invention discloses a network security situation awareness and analysis platform based on AI, and relates to the technical field of network security situation awareness and analysis, and the platform comprises a multi-source data collection module which integrates flow, logs, assets and threat intelligence data, and carries out encryption transmission and standardization; the data preprocessing module purifies and optimizes data, and guarantees data quality and sensitive information security; the AI situation awareness analysis module extracts features through a deep learning model, dynamically evaluates the situation and identifies threats; the threat early warning and decision-making module triggers graded early warning and generates a targeted emergency response scheme; the visual display and interaction module displays information in multiple dimensions and supports query and report generation; and the data storage and tracing module adopts a mixed storage architecture, so that the data security and traceability are ensured. The platform integrates multi-source data and realizes situation accurate perception and intelligent decision by means of an AI technology; the early warning is accurate, the visual interaction is convenient, and the intelligent and efficient level of network security protection is comprehensively improved.
Owner:HUNAN CONGMAO TECH CO LTD

Network security situation awareness method and system and computer equipment

The invention provides a network security situation awareness method and system and computer equipment, and belongs to the technical field of network security. The method comprises the following steps: collecting and standardizing multi-source heterogeneous security data; constructing and dynamically updating a network asset and vulnerability knowledge graph; performing tactical labeling on the security event based on tactical, technology and process behavior model libraries to form a current attack context state; mapping the current state into a knowledge graph to deduce a potential subsequent attack path; performing quantitative risk assessment on the path, and calculating an initiation probability and a potential risk value; outputting situation awareness information containing the path and the probability and risk value thereof; and dynamically determining a key area needing to be updated preferentially in the knowledge graph according to an evaluation result, and triggering incremental updating. According to the method, the crossing from static monitoring to dynamic prediction is realized, the attack path can be actively deduced, quantitative risk assessment is carried out, meanwhile, the real-time performance of the knowledge graph is guaranteed through a focusing updating mechanism, and the initiative and accuracy of network security protection are improved.
Owner:SICHUAN RUIFANGDA TECHNOLOGY CO LTD

Network security situation awareness method based on artificial intelligence

The invention provides a network security situation awareness method based on artificial intelligence, and relates to the technical field of network security. Real-time monitoring and multi-source data fusion analysis are performed on a network communication behavior, a host operation state, threat alarm information and a relationship between vulnerabilities and a topological structure; constructing a threat intensity parameter, a behavior anomaly rate parameter, a vulnerability exposure degree parameter and a traffic anomaly density parameter, and calculating a risk potential energy index to realize quantitative evaluation of a network risk state; introducing an attack chain dynamic coupling index to perform dynamic analysis on a multi-stage attack evolution trend, and judging an attack chain formation risk; depicting an abnormal flow distribution concentration degree through a risk propagation convergence entropy index, and identifying concentrated penetration and critical path breakthrough risks; and defense strategies such as risk tracing, attack chain blocking and key path reinforcing are given, so that accurate recognition, trend prediction and adaptive defense of complex network attacks are realized.
Owner:CHENGDU RUIDIOU TECH CO LTD

Network security situation awareness method based on Transform and time sequence prediction

The invention belongs to the technical field of network security, and discloses a Transform and time sequence prediction-based network security situation awareness method, which comprises the following steps of: performing multi-level feature engineering on traffic data subjected to quality monitoring, and extracting three layers of 78-dimensional features; a situation assessment model based on Transform is constructed, and continuous situation scores are output through association between multi-head self-attention learning features; the continuous situation scores are aggregated according to a time window to form a situation score sequence, and a future situation is predicted by a mixed architecture of a Transform encoder and an LSTM decoder, so that coupling cooperation of evaluation and prediction is realized. According to the method, the real-time performance is guaranteed, meanwhile, good engineering practicability is achieved, and the flow record is converted into the situation scoring sequence with remarkable autocorrelation through window aggregation, so that the short-time prediction stability and learnability are improved.
Owner:NANJING UNIV OF POSTS & TELECOMM

Network security situation awareness and automatic response decision-making system based on AI

The invention discloses a network security situation awareness and automatic response decision-making system based on AI, and the system comprises a multi-source data processing module which is used for collecting multi-source data, executing time synchronization, field standardization and feature extraction, and generating a security event vector sequence; the situation modeling module is used for one-dimensional mapping and cross-source combination to form a situation representation vector; the attack relation modeling module is used for constructing a behavior combination structure and generating attack chain stage probability distribution and path contribution degree; the trend prediction module is used for extracting continuous time slices and inputting a time sequence modeling structure to generate a risk trend prediction result; the response strategy generation module is used for generating an optimal response action; and the closed-loop updating module is used for executing actions and updating parameters of each modeling module according to feedback information. According to the method, the multi-source security events are uniformly modeled based on the KAN network, so that collaborative updating of attack relation depiction, risk prediction and response generation is realized.
Owner:WUHAN DONGHU UNIV

Network security situation awareness method and system based on large model and threat assessment

InactiveCN121907597ASecuring communicationHigh level techniquesLinguistic modelSecurity association
The invention relates to the technical field of network security, in particular to a network security situation awareness method and system based on a large model and threat assessment. The method comprises the following steps: firstly, acquiring and standardizing multi-modal security data in a cloud service environment in real time, distributing a behavior modal cluster for security event metadata through clustering analysis, and generating a security feature vector containing business semantics and behavior dynamic features based on a cluster center relocation technology; then constructing a local situation map reflecting asset topology and an access link by using a cloud security association model; semantic reasoning is performed on the atlas through a large language model, an attack intention is recognized, and an attack path is predicted; and finally, combining the path probability, the asset value and the vulnerability feature to quantitatively calculate a risk index, and automatically generating a response strategy. Semantic compression of massive logs is realized through modal clustering, and the calculation bottleneck of processing original data by a large model is overcome; and in combination with graph correlation and large model reasoning, the crossing from passive warning to active intention prediction is realized.
Owner:BEIJING ZHONGCHUANG HAISHENG TECHNOLOGY CO LTD

Information security comprehensive protection system of production enterprise

The invention discloses a production enterprise-oriented information security comprehensive protection system, which comprises a unified security management center, a region boundary protection module, a security computing environment module, a data full life cycle protection module, an authority management module, a threat active defense module and a network security situation awareness module, original dispersed and isolated safety capabilities are integrated into a linkage system through an integrated architecture of a unified safety management center and six functional modules through a unified interface / event bus, so that instant isolation and authentication of a transverse production control area, a management information area and a longitudinal remote operation and maintenance channel are realized, and the transverse penetration blocking rate is remarkably improved; role isolation and dynamic authorization are realized through the authority management module, the attack surface of a supply chain is greatly narrowed, the manual operation and maintenance workload is reduced by about six percent, and the overall safety toughness and operation efficiency of an enterprise are remarkably improved.
Owner:HENGTONG PRECISION COPPER FOIL TECHNOLOGY (DEYANG) CO LTD

A centralized control station network security situation awareness method and system

This application proposes a method and system for network security situation awareness at a centralized control station, belonging to the field of network security communication technology. The method includes: acquiring multi-source operational datasets corresponding to each sensing node in the centralized control station's sensing node set; extracting multi-dimensional feature vectors from each sensing node and performing feature offset analysis to obtain multi-dimensional offset feature vectors; calculating the degree of newness index of each sensing node; classifying the sensing node set into multiple levels by analyzing the degree of newness index to obtain multi-level sensing layers; constructing corresponding multi-level attack behavior detection models; and calling the multi-level attack behavior detection models to perform attack behavior risk detection on sensing nodes belonging to each level of sensing layer. By adaptively hierarchically modeling based on the degree of newness of sensing nodes, targeted attack behavior detection strategies are adopted for sensing nodes with different degrees of newness, thereby improving the accuracy and timeliness of network security situation awareness at the centralized control station in scenarios of dynamic node expansion.
Owner:BEIJING KEDONG ELECTRIC POWER CONTROL SYST CO LTD +2

A method and device for network security situation awareness

This application relates to the field of network situational awareness technology, and discloses a method and device for network security situational awareness. The method includes: identifying regulatory entities and collecting abnormal events; identifying interactive and operational behaviors as risk characteristics; constructing a first risk identification model and deploying it on an edge terminal; collecting the type and sensitivity attributes of the regulatory entities; dynamically forming regulatory assistance pairs based on the attributes; generating a second risk identification model by weighted averaging of the parameters of the first model based on the regulatory assistance pairs and deploying it in the cloud; real-time interactive data is preferentially screened by the cloud-based second model; if a risk is identified, a structured report is generated and distributed; if not identified, it is reviewed by the first model at the edge terminal. This application achieves distributed intelligent perception with cross-domain collaboration and data not leaving the domain, solving the model bias and centralized delay problems caused by insufficient samples of a single entity, and significantly improving detection accuracy, response efficiency, and collaborative defense capabilities in low-sample scenarios.
Owner:STATE GRID BEIJING ELECTRIC POWER CO

Network security situation awareness method and system based on deep learning

The invention relates to the field of network security, and discloses a network security situation awareness method and system based on deep learning, and the method comprises the following steps: obtaining multi-source network data; extracting time feature representation of nodes in the dynamic space-time diagram sequence through a multi-scale time feature extraction network; extracting spatial feature representation of the nodes through a graph neural network; fusing the time feature representation and the spatial feature representation; constructing a decoupling encoder based on the information bottleneck; and performing anomaly detection and attack path tracing based on the time hidden variable, the space hidden variable and the coupling hidden variable. By constructing a multi-scale time feature extraction network and introducing a dynamic receptive field adjustment mechanism, space-time coupling features are separated into a time hidden variable, a space hidden variable and a coupling hidden variable, and coupling information is comprehensively utilized during anomaly detection to improve detection precision. And an attack propagation path is accurately reconstructed based on pure spatial features during attack path tracing.
Owner:若昊新程(北京)科技有限公司

Self-adaptive network security situation awareness method and device combined with online learning

The invention provides a self-adaptive network security situation awareness method and device combined with online learning, and the method comprises the steps: collecting real-time network state data and system load index data of a preset data source, carrying out the preprocessing of the data to form a multi-modal time sequence segment, inputting a pre-training time sequence data prediction model activated by employing Monte Carlo Dropout through a sliding window, and carrying out the prediction of the real-time network state data and system load index data. The method comprises the following steps of: calculating a prediction value of a next time period, outputting a prediction value and an uncertainty quantity of the next time period, calculating a threat probability through historical residual probability distribution fitting, realizing double-index risk assessment based on a preset threshold interval system, dividing into three types of states, and finally, respectively triggering online learning, configuration maintenance or intervention disposal flow for different states. According to the method, by introducing uncertainty quantized double-index evaluation and state-driven online learning closed loop, crossing of network security situation awareness from static detection to dynamic self-adaption is achieved, and the two core problems of insufficient real-time performance and concept drift in an edge computing scene are effectively solved.
Owner:BEIJING UNIV OF POSTS & TELECOMM

An artificial intelligence-based network security situation awareness method

The application discloses a network security situation awareness method based on artificial intelligence, comprising the following steps: collecting multi-source heterogeneous data to generate a standardized data set; decoupling space-time characteristics to separate space-time dimension characteristics; fusing space-time cross attention to output fused space-time characteristic vectors; constructing a causal reasoning engine to output a dynamic causal diagram and a counterfactual reasoning result set; constructing a dynamic risk propagation model to output a full asset risk value matrix and a risk propagation path diagram; generating a situation quantization matrix, constructing an adversarial training decision network, and outputting a defense strategy set verified by adversarial training; automatically generating a strategy; and man-machine collaborative verification closed loop. Through space-time characteristic decoupling and the causal reasoning engine, the application realizes dynamic reconstruction of a threat propagation path, reduces risk positioning error; in combination with the adversarial training decision network, the application makes the defense strategy have a reduced misjudgment rate in the simulation APT attack test.
Owner:BEIJING BEILONG YUNHAI NETWORK DATA TECH CO LTD

A Deep Learning-Based Network Security Situation Awareness Method and System

PendingCN122316711AData packArea network
This invention discloses a network security situation awareness method and system based on deep learning, relating to the field of deep learning technology. The method includes deploying a network security data acquisition component within a regional network to collect and parse network data packets, generating security event data; constructing a communication graph of network communication relationships based on the security event data, and embedding and mapping the communication edge features in the communication graph to generate communication edge embedding vectors as a vectorized representation of communication relationships; performing topology encoding based on the communication graph to generate position codes, and fusing the communication edge embedding vectors with the position codes to form fused edge vectors containing network topology information; introducing a multi-head attention mechanism to update the fused edge vectors to obtain the final edge vectors. This invention can not only more accurately identify and distinguish different types of attack behaviors, but also significantly improve the accuracy of network security status perception.
Owner:FUJIAN HUADIAN KEMEN POWER GENERATION CO LTD

Network security situation awareness method and system for signal creation environment

PendingCN122339805AIt innovationAttack
This invention relates to the field of network security technology, specifically to a network security situation awareness method and system for the domestic IT innovation environment. The method includes: extracting attack sub-links from a directed graph of entity relationships based on entity log data across different time periods; assigning risk indicators to each entity based on the attack sub-links; selecting predicted complete links for each attack sub-link; assigning association relationships to different attack sub-links based on the attack sub-links traversed by all predicted complete links, and determining the complete attack link accordingly; updating the entity's risk indicators based on the obtained complete attack links, and re-acquiring a more accurate complete attack link. This invention can intelligently associate and iteratively optimize attack fragments across time periods, effectively reconstructing the attacker's complete intent and improving the accuracy and reliability of situation awareness in the complex domestic IT innovation environment.
Owner:BEIJING GUANGYIN JIAYE TECHNOLOGY CO LTD

Energy private network security situation awareness method and system fusing internet of things and artificial intelligence

This application discloses a method and system for network security situation awareness of a private energy network integrating the Internet of Things (IoT) and artificial intelligence. The method includes: extracting frequency fluctuation feature sequences and communication interaction data based on the energy network's operating frequency signal and the network communication data stream; constructing a unified frequency-time reference axis for the entire network, mapping the communication interaction data to the frequency-time reference axis, and generating a frequency-anchored data sequence; performing semantic parsing on the energy network protocol messages in the communication interaction data, constructing a semantic representation of control commands and their expected physical effects model; performing semantic-temporal consistency verification to obtain semantic-physical coupling residuals; calculating the temporal reliability score of the communication data and identifying abnormal control behaviors; inputting the temporal reliability score and abnormal control behaviors into a preset situation assessment model, and outputting the network security situation value of the private energy network. This application improves the accuracy of network security situation detection.
Owner:GUIZHOU INST OF COAL SCI +1

Low-delay network security situation awareness system based on artificial intelligence

The invention discloses a low-delay network security situation awareness system based on artificial intelligence, which relates to the technical field of Internet of Things security and comprises a dynamic awareness topology reconstruction module, an edge gateway module, a terminal security agent module, a situation assessment and anomaly recognition engine module, a cross-domain linkage engine module and a situation early warning and visualization module. According to the method, a dynamic network security management closed loop is constructed, a terminal state is collected by a topology reconstruction module, a sensing cluster is established and topology is reconstructed, an edge gateway summarizes equipment operation data, a situation assessment and anomaly recognition engine analyzes and recognizes network anomaly and an attack link through model fusion, and a cross-domain linkage engine generates a protection instruction. And the terminal security agent executes operation, and the situation early warning and visualization module realizes global display and graded early warning, so that the problems of poor static topology adaptability, high data transmission delay and disjunction of situation assessment and protection response in the prior art are solved, and reliable security guarantee is provided for the dynamic network of the Internet of Things.
Owner:GUANGZHOU SIYUN DATA TECH CO LTD

Special protocol message cross-space semantic association reasoning method and system for power monitoring system

The invention discloses a special protocol message cross-space semantic association reasoning method and system for an electric power monitoring system, and aims to solve the problems that protocol analysis and system security events are isolated and advanced threats are difficult to associate in existing monitoring. The method comprises the following steps: jointly analyzing a protocol transmission time sequence through Fourier transform, wavelet transform and an intelligent time sequence prediction model, and constructing a fine-grained time characteristic baseline; a sensing agent is deployed on a host, a database, security and protection equipment and other layers, and formatted security events are collected; and designing an intelligent association engine fusing graph representation learning and rule reasoning, carrying out deep semantic association on an abnormal protocol mode and a cross-level security event, and realizing accurate threat alarm based on a business behavior full-link model of reinforcement learning self-optimization. According to the method, intelligent cross-space reasoning from network protocol microscopic abnormity to system macroscopic threat is realized, and the precision, the intelligent level and the adaptive capability of network security situation awareness of the intelligent substation are greatly improved.
Owner:ZHANGZHOU POWER SUPPLY COMPANY STATE GRID FUJIANELECTRIC POWER +1

Network security situation awareness method based on knowledge graph

The invention belongs to the technical field of information security data processing, and particularly relates to a knowledge graph-based network security situation awareness method, which comprises the following steps of: extracting entity interaction logic in network traffic data, and constructing a topological association graph structure; obtaining threat diffusion intensity based on the alarm weight of the active path, the connection closeness and the total number of nodes; a saturation control function is utilized, a compensation correction value is obtained according to the real-time background flow load and the historical average safety reference flow, and self-adaptive suppression of reference drift generated by service fluctuation is achieved; and based on the compensation correction value and the diffusion intensity difference value, obtaining a whole network situation index in combination with the sudden change gain, and executing closed-loop adaptive control of firewall banning and equipment parameter adjustment. According to the method, the problems that threat diffusion intensity is difficult to evaluate and false alarms are easily generated due to service fluctuation interference in the prior art are solved, and capture of network threat instantaneous outbreak characteristics and resource allocation are realized.
Owner:SHANDONG ZHENGZHOU INFORMATION TECHNOLOGY CO LTD

Network data asset surveying and mapping and asset portraying system and method

The invention provides a network data asset surveying and mapping and asset portraying system and method, and the system comprises an asset scanning detection module which is used for carrying out the full-port and full-protocol scanning of an IP address in a target network range, so as to find active assets; the asset information analysis module is used for collecting and analyzing multi-dimensional information of the active assets; the asset portrait construction module is used for constructing a structured portrait of the asset based on the multi-dimensional information; and the data synchronization log module is used for synchronizing the structured portrait data to a distributed log convergence device, and can automatically generate a unified structured asset portrait which is comprehensive in coverage, rich in information and contains an association relationship between assets. Therefore, an accurate and reliable data footstone is provided for network security situation awareness, attack surface evaluation and emergency response.
Owner:HUANENG INFORMATION TECH CO LTD

Power grid communication network security situation awareness method

The invention relates to the technical field of situation awareness, and discloses a power grid communication network security situation awareness method, which comprises the following steps of: performing time sequence normalization processing on multi-source heterogeneous security logs and traffic data of a power grid network to obtain a multi-source security data set; performing power protocol association analysis on the multi-source security data set to obtain a security event sequence; constructing a power grid attack knowledge graph; performing association matching on the security event sequence and the power grid attack knowledge graph, and performing adaptive sensitivity weight evaluation on the operation state information of the power grid network to obtain a threat judgment result and confidence; carrying out situation analysis and quantification on the asset importance and the real-time load level of the power grid network to obtain a comprehensive security situation index; mapping the comprehensive security situation index to a preset early warning strategy response library to obtain an early warning signal and a protection strategy; according to the invention, the efficiency of power grid communication network security situation awareness can be improved.
Owner:NANJING FANGNENG AUTOMATION EQUIP CO LTD

Artificial intelligence based cyber security situation awareness method and system

PendingCN122348853AStream dataEngineering
The application provides an artificial intelligence-based network security situation awareness method and system. By acquiring and processing network security awareness flow data sequences, the starting and ending of threat mode events are located, the target events of intrusion activities in each network security awareness flow data are located, the boundary nodes of threat mode events are determined by calculating the connection degree between the network security situation vector sets corresponding to these target events, and the events where the intrusion migration nodes and intrusion persistence nodes are located are accurately identified according to the boundary nodes for each network security awareness flow data. Through in-depth analysis of the intrusion migration characteristics and the intrusion persistence characteristics of these events, accurate intrusion migration nodes and intrusion persistence nodes are generated. Finally, based on the comprehensive information of the intrusion migration nodes and the intrusion persistence nodes, the intrusion activities in each network security awareness flow data are determined, and the comprehensive and real-time awareness of the network security situation is realized.
Owner:WUHAN ZHONGYUN INTERNET TECH CO LTD

Digital mine network security situation awareness method and system

The invention belongs to the technical field of industrial internet security, and particularly relates to a digital mine network security situation awareness method and system, and the method comprises the following steps: S1, accessing the network flow of a mine industrial switch, deconstructing a data packet into an instruction domain, an address domain and a load domain through protocol analysis, and extracting a timestamp and the binary content of each domain; s2, calculating the Shannon entropy of the protocol field in the current time window, and calculating the abnormal entropy increase index of the protocol field according to the average entropy value and the standard deviation under the historical normal working condition, thereby evaluating the hidden channel risk; and S3, extracting physical values in the continuous data packets, and calculating a physical inertia conflict coefficient according to the maximum change rate allowed by the physical parameters of the equipment. According to the method, the physical law is introduced as a safety criterion, so that the false alarm rate is effectively reduced, and precise perception of advanced persistent threats is realized.
Owner:CHINA ELECTRIC CLOUD INFORMATION TECH CO LTD

Bank informatization and network security situation awareness system

The invention relates to the technical field of network security and situation awareness, and discloses a bank informatization and network security situation awareness system, which comprises a data acquisition module used for capturing all traffic information passing through a server in a monitoring range, a data processing module used for converting numerous data types into recognizable contents, and a processing module used for processing the recognizable contents. The system comprises a data acquisition module, a feature analysis module, a security system protection module, a situation evaluation and calculation module, a situation prediction and traceability module, a data analysis module, a data analysis module, a data analysis module, a data analysis module, a data analysis module and a data analysis module, wherein the data analysis module is used for acquiring data and extracting data features; the security system protection module is used for protecting the overall security of a bank network; and the interface display and management module is used for displaying the network security condition and supervising the action of an administrator, so that comprehensive protection and predictable protection of bank network security are realized, and the security degree of bank information is greatly improved.
Owner:NANJING CYBERTRON TECHNOLOGY CO LTD

Network security analysis system and method based on security situation awareness system

InactiveCN121967013AEliminate technical barriersimprove data qualitySecuring communicationTimestampOriginal data
The invention discloses a network security analysis system and method based on a security situation awareness system, and relates to the technical field of network security situation awareness, and the system comprises a data collection module, a processing module, an event reconstruction module, a threat analysis module and a situation generation module which cooperate in sequence. The data acquisition module acquires original data containing encrypted traffic and unstructured alarm from a network boundary probe; the data processing module performs hierarchical decoding and normalization on the data to generate a standardized record with a unified timestamp; the event reconstruction module connects the records into a continuous event sequence according to a time sequence; the threat analysis module compares the event sequence with a threat behavior pattern library, and identifies and marks fragments conforming to an attack chain; and the situation generation module constructs a network security situation portrait accordingly. According to the scheme, effective analysis of encrypted and unstructured security data is realized, a complex and latent attack behavior chain can be identified based on the continuous event sequence, and the depth and accuracy of threat detection are improved.
Owner:INFORMATION & COMM CO OF STATE GRID SHAANXI ELECTRIC POWER CO LTD

A method and system for network security situation awareness based on honeycomb drive

ActiveCN122027363BPathPingPropagation delay
The application provides a network security situation awareness method and system driven by a honeynet, and relates to the technical field of network security management.The method provided by the application comprises the following steps: receiving threat event reporting from a honeynet trapping node, extracting an attacker behavior path, session content and triggering features, and performing first attack path correction according to the node's own topology position and attack flow information; when there are multiple honeynet trapping nodes simultaneously capturing events from the same attack source, the propagation delay and path deviation of the attack chain in the network are calculated through time synchronization and event matching between the honeynet trapping nodes, the attack situation is adjusted in real time, and the projection error of the attack propagation path in the network topology is corrected. The perception system realizes the collaborative work of distributed trapping nodes by introducing a honeynet driving mechanism, calculates the propagation delay and path deviation of the attack chain through time synchronization and event matching, and greatly improves the spatial accuracy of threat positioning.
Owner:INFORMATION & COMMNUNICATION BRANCH STATE GRID JIANGXI ELECTRIC POWER CO +1

Network security situation awareness method and system

The invention discloses a network security situation awareness method and system, and relates to the technical field of network security, and the method comprises the steps: carrying out the network abnormal fluctuation analysis based on a current network behavior data set through employing a short-term sensitivity threshold; carrying out transmission anomaly influence analysis based on the network anomaly fluctuation data; determining an internal pressure bearing index based on the internal state parameter of the key business service; determining a target contribution weight based on the internal pressure bearing index, and generating an internal transmission problem influence factor based on the target contribution weight so as to determine the security vulnerability of the network assets in combination with the network abnormal fluctuation data and the transmission abnormal influence data; performing vulnerability utilization probability analysis based on the current network behavior data set to determine a network threat severity; and performing network overall security situation assessment based on the network threat severity and the network asset security vulnerability. According to the method, comprehensive and dynamic evaluation of the overall security situation of the network is realized, and the problems of evaluation lagging and splitting of a traditional method are effectively solved.
Owner:GUANGZHOU XIAOCHI TECH CO LTD

Centralized control station network security situation awareness method and system

The invention provides a centralized control station network security situation awareness method and system, and belongs to the technical field of network security communication. The method comprises the following steps: acquiring a multi-source operation data set corresponding to each sensing node in a sensing node set of the centralized control station, extracting a multi-dimensional feature vector of each sensing node, and performing feature offset analysis to acquire a multi-dimensional offset feature vector; calculating a newly-added degree index of each sensing node; and classifying the sensing node set by analyzing the newly added degree index to obtain multiple levels of sensing layers, constructing a corresponding multi-level attack behavior detection model, and calling the multi-level attack behavior detection model to execute attack behavior risk detection of the sensing node to which each level of sensing layer belongs. Self-adaptive hierarchical modeling is carried out according to the newly-added degrees of the sensing nodes, and targeted attack behavior detection strategies are adopted for the sensing nodes with different newly-added degrees, so that the accuracy and timeliness of network security situation sensing of a centralized control station in a node dynamic expansion scene are improved.
Owner:BEIJING KEDONG ELECTRIC POWER CONTROL SYST CO LTD +2

Network security situation awareness system and method based on multi-source awareness

The invention discloses a network security situation awareness system and method based on multi-source awareness, and relates to the technical field of network security. Network working records are utilized to form a network topological graph, and network data twin bodies are constructed; determining an attacked entity and an enhanced digital twin; the vulnerability measure, the threat activity level and the abnormal behavior deviation degree of each network entity are calculated through an enhanced digital twinborn body, the comprehensive risk score of each network entity is obtained through weighted fusion calculation, an attack rule base is constructed, all attack rules in the attack rule base are utilized to perform automatic evolution to obtain an attack path, and the attack path is subjected to attack processing. Integrating all attack paths to form a probability attack graph; and calculating the risk value of each attack path in the probability attack graph, pre-defining different candidate mitigation measures for the state transition edge of each attack path in the key attack path list, performing simulation execution in the enhanced digital twin, and selecting the optimal candidate mitigation measure for recommendation.
Owner:NANJING BIG DATA SECURITY TECH CO LTD

Novel power grid alarm analysis method and device based on network security situation awareness

The invention relates to the technical field of power grid dispatching automation security, in particular to a novel power grid alarm analysis method and device based on network security situation awareness, and the method comprises the steps: S1, constructing a multi-dimensional index system; s2, data acquisition and preprocessing; s3, positioning and judging data; s4, performing comprehensive evaluation and alarm decision making; and S5, alarm information generation and closed-loop management. According to the scheme, the power grid state data is mapped to the multi-dimensional space for positioning analysis by constructing the multi-dimensional coordinate system fusing multiple indexes. According to the method, the Mahalanobis distance is combined with the triple boundary calibration method, the normal operation interval of each dimension is defined, when a data point deviates from a super-rectangular normal area, the boundary crossing degree is calculated through the Manhattan distance, classification and recognition of single-axis anomaly, double-axis cross anomaly and composite anomaly are achieved, the alarm accuracy is effectively improved, and the alarm efficiency is improved. Therefore, the operation and maintenance personnel can quickly lock the abnormal type and position, and the processing efficiency and accuracy of emergency situations are greatly improved.
Owner:STATE GRID GANSU ELECTRIC POWER RESEARCH INSTITUTE

Network security situation awareness analysis system and use method

The invention discloses a network security situation awareness analysis system and a use method, and relates to the technical field of network security situation awareness. The system comprises a federated learning semantic alignment fusion module, a situation-driven encryption self-adaption module, a digital twinborn situation prediction deduction module and a knowledge graph-large model interpretable traceability module. The federated learning module guarantees the multi-source data fusion efficiency and privacy through preprocessing, semantic alignment and homomorphic encryption; the encryption module dynamically switches an algorithm and a key period according to the threat level; the twinborn module constructs virtual mapping, predicts threats in combination with reinforcement learning and screens an optimal defense scheme; and the traceability module generates a report containing an evidence chain and feeds back optimization. The use method is executed according to the steps of data collection and fusion, situation prediction and encryption adjustment, defense deduction and tracing and closed-loop optimization, the problems that multi-source heterogeneous data fusion is difficult, the privacy leakage risk is high, threat defense lags and tracing is fuzzy are solved, and the safety and efficiency of situation awareness are improved.
Owner:XUZHOU COLLEGE OF INDAL TECH