Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

315 results about "Network segment" patented technology

A network segment is a portion of a computer network. The nature and extent of a segment depends on the nature of the network and the device or devices used to interconnect end stations.

Asset vulnerability detection method and device, electronic equipment and storage medium

The invention discloses an asset vulnerability detection method and device, electronic equipment and a storage medium, and relates to the technical field of network security, and the method comprises the steps: actively sending a multi-protocol detection packet to scan a target network segment, and obtaining a first asset set; passively monitoring network traffic to extract asset feature information, and obtaining a second asset set to generate an asset list; port scanning tasks of all assets are dispatched to a plurality of scanning nodes in a distributed and parallel mode, dynamic port scanning is carried out according to a descending order of a plurality of key elements in combination with a port scanning optimization model based on risk prediction, and a full-amount port risk map is constructed; the static layer is matched with known vulnerabilities; the dynamic layer identifies suspicious behaviors deviating from a normal behavior baseline through an anomaly detection algorithm, and obtains an asset vulnerability detection result in combination with a cross validation method; according to the invention, the detection requirements of asset full coverage and early threat discovery in a complex network environment are met.
Owner:GUANGDONG ORIENTAL THOUGHT TECH

Method and apparatus for traffic scheduling implementation, device, storage medium, and program product

The present disclosure provides a method of traffic scheduling implementation, including: receiving a domain name resolution request sent by a first business application on a first terminal device, and performing domain name resolution on the domain name resolution request to determine a to-be-resolved domain name; if the to-be-resolved domain name is a target domain name, determining, from a preset network segment, a first virtual network address corresponding to the to-be-resolved domain name, and using the first virtual network address as a first traffic destination address corresponding to the to-be-resolved domain name, where the preset network segment includes a plurality of virtual network addresses; and sending the first traffic destination address to the first business application on the first terminal device, to cause the first business application to perform data transmission based on the first traffic destination address.
Owner:BEIJING VOLCANO ENGINE TECH CO LTD

Segment scanning type DDoS attack detection method and device, electronic equipment and storage medium

The invention discloses a segment scanning type DDoS attack detection method and device, electronic equipment and a storage medium. The detection method comprises the following steps: for each IP address in a plurality of IP addresses, acquiring a first traffic feature set comprising traffic features of N dimensions of a first traffic set taking the IP address as a destination IP address in a first time period; calculating weights respectively corresponding to the traffic characteristics of the N dimensions based on a historical traffic set; corresponding weights are given to the traffic features of the N dimensions of the IP address, and a second traffic feature set corresponding to the IP address is obtained; clustering the plurality of IP addresses based on a plurality of second traffic feature sets corresponding to the plurality of IP addresses to obtain a clustering result; and determining the IP address network segments subjected to the segment scanning type DDoS attack in the IP address network segments where the plurality of IP addresses are located based on the clustering result. According to the method and the device provided by the embodiment of the invention, the segment scanning type DDoS attack can be effectively detected, the false alarm and the missing alarm are reduced, and the network security is improved.
Owner:BEIJING VOLCANO ENGINE TECH CO LTD

Efficient split management in a virtual switch using a spanning tree

A network device of a virtual switch, which includes a second network device and operates on a unified control plane, is provided. During operation, the network device maintains a link between its first port and a second port of the second network device. Here, the first link can be distinct from a second link used for exchanging data traffic of the virtual switch. The network device operates a spanning tree protocol to place the first and second ports in respective port states, which include a forwarding state and a blocked state. If the second link becomes unavailable, the network device determines that the virtual switch has split into a first segment comprising the network device and a second segment comprising the second network device. If the first port state is in the blocked state, the network device suspends communication via a respective port of the first segment.
Owner:HEWLETT PACKARD ENTERPRISE DEV LP

Load balancing secure network traffic

Techniques for load balancing secure network traffic are disclosed. A system, process, and / or computer program product for load balancing secure network traffic includes monitoring network traffic for one branch of a plurality of branches for an enterprise network, and splitting the network traffic of the one branch into a plurality of network segments based on a determination that the network traffic exceeds traffic capacity of at least one security processing node (SPN) of a plurality of SPNs using a network load balancer (NLB) in communication with a plurality of Network Processing Nodes (NPNs), the plurality of monitored branches being distributed to the plurality of SPNs via a plurality of tunnels.
Owner:PALO ALTO NETWORKS INC

Train communication address allocation method, electronic equipment and storage medium

PendingCN121217702ATransmissionMarshallingNetwork addressing
The invention discloses a train communication address allocation method, electronic equipment and a storage medium, and the method comprises the steps: carrying out the detection interaction between train-level backbone network modules of each train to determine a subnet segment corresponding to each train, and receiving an address request of local target equipment based on an Ethernet train composition module of each train, the unique network address is allocated based on the subnet segment, so that the technical problems of low efficiency, easy conflict and incapability of adapting to flexible marshalling requirements caused by manual configuration of the communication address during marshalling adjustment of the existing train are solved, automatic allocation of the train communication address is realized, the marshalling adjustment time is greatly shortened, address conflict is avoided, and the marshalling adjustment efficiency is improved. And meanwhile, different marshalling switching is adapted to meet diversified operation requirements.
Owner:CRRC DALIAN CO LTD

Method for implementing zero trust role-based microsegmentation based on network switch and network controller and access switch using the same

There is provided a method for implementing a zero trust role-based microsegmentation based on a network switch. The method includes steps of: (a) registering, by a network controller, the specific network device in a specific segment among preset segments by referring to asset information corresponding to the specific network device; and (b) transmitting, by the network controller, a specific segment ID corresponding to the specific segment to the access switch, to thereby instruct the access switch to assign the specific segment ID as metadata to a specific MAC address of the specific network device by using VACL, and control an access of the specific network device to the network resources based on at least one specific resource access control rule corresponding to the specific segment ID by using IACL.
Owner:PIOLINK

Local area network system and backbone network system

The invention provides a local area network system and a backbone network system, belongs to the technical field of computers, and particularly relates to the technical field of communication, computer networks, routing and fault detection. According to the specific implementation scheme, the regional network system comprises a plurality of network nodes, each network node comprises a plurality of detectors and a plurality of forwarding devices, the detectors are in communication connection with the forwarding devices respectively, and the forwarding devices are in communication connection with the forwarding devices included in the other network nodes respectively; wherein the forwarding equipment is used for receiving a data packet and forwarding the data packet to the detector determined based on a destination address of the data packet under the condition that the destination address of the data packet belongs to a first routing network segment of the forwarding equipment; and the detector obtains fault information based on the received data packet.
Owner:BEIJING BAIDU NETCOM SCI & TECH CO LTD

Communication protocol for inference of physical slot identifier by baseboard management controller of blade server

ActiveUS12531938B2User identity/authority verificationBroadcast domainEthernet frame
This disclosure describes techniques for interoperability of a blade server in a server chassis, where IOMs of the server chassis do not provide dedicated pins for communicating a physical slot ID to the blade server. BMCs of the blade servers and CMCs of IOMs of the server chassis are mutually configured to broadcast Ethernet frames on layer 2 network segments over a broadcast domain configured by a switch module connected to the blade servers over layer 2 network segments; conduct a slot inference communication protocol using these Ethernet frame broadcasts to enable the CMC to determine a physical slot ID in response to a BMC request, and broadcast that physical slot ID back to the BMC; and use a public certificate-private certificate pair, based in a hardware root of trust, to enforce security of this communication protocol.
Owner:CISCO TECHNOLOGY INC

Agent surveying and mapping method and system for isolated network blind area asset discovery

The invention relates to the technical field of network security and information, in particular to an Agent surveying and mapping method and system for isolating network blind area asset discovery, and the method comprises the steps: deploying an Agent at a terminal, collecting local data including an ARP cache, a network connection table, a hardware fingerprint and a behavior portrait, and encrypting and uploading the local data. The main control center performs asset deduplication and identity verification based on hardware fingerprints, processes connection data by using a time window alignment and session continuity analysis algorithm to solve association ambiguity caused by time sequence dislocation and temporary connection, and establishes a cross-Agent connection relationship with high confidence. And finally fusing the connection relation and behavior portrait data, and incorporating the data into unmanaged assets found by a link layer to synthesize a global asset topology of a cross-logic network segment. According to the method, the coverage rate, the identification accuracy and the real-time performance of asset discovery in a complex isolation network environment are improved, and meanwhile, the interference risk of a scanning process on a service network is eliminated.
Owner:CHINA RAILWAY XIAN GRP CO LTD

Method and device for converting text programming language into graphical programming language

The invention relates to the technical field of programming language conversion, in particular to a method and device for converting a text programming language into a graphical programming language, and the method comprises the steps: converting an input text programming language source code into a structured program-network segment-row-element lattice level data object, generating a text programming language list taking the network segment as a unit; traversing the text programming language list, retrieving a keyword instruction in the text programming language list according to the text programming language protocol, performing region splitting and analysis, generating graphic region information blocks, and storing the graphic region information blocks in a graphic region general list; after processing of all text lines in the current network segment is completed, normalization processing is carried out on the graphic area general table, and conversion of the network segment from a text programming language to a graphic programming language data structure is completed; and summarizing the conversion results of all the network segments to form a complete graphical programming language program. And the conversion efficiency from the text programming language to the graphical programming language is improved.
Owner:JINAN BODOR LASER CO LTD

Resource allocation method and device for secure resource pool, equipment and storage medium

The invention provides a resource allocation method and device for a security resource pool, equipment and a storage medium. The method comprises the following steps: acquiring the type, specification, service logic and address of a security instance required by a tenant; based on an allocable resource group of the resource pool, screening a node matched with the type and the specification, and allocating a security instance of the node for the tenant; constructing a service chain according to the business logic; the diverter creates a VLAN-IF interface for a tenant, binds a service chain and configures a first route and a second route according to a tenant address, a source network segment of the first route is a tenant address, an incoming interface is a first interface of the diverter, an outgoing interface is the VLAN-IF interface, flow flows into the diverter from the first interface and is transferred to the service chain through the VLAN-IF interface, a destination network segment of the second route is the tenant address, and the tenant address is a tenant address. The input interface is a VLAN-IF interface, the output interface is a first interface of the shunt, and the flow processed by the service chain flows into the shunt from the VLAN-IF interface and is returned to the tenant through the first interface.
Owner:HANGZHOU DPTECH TECH

Managing a delay of network segments in an end-to-end communication path

Embodiments of systems and methods for managing a delay of network segments in an end-to-end communication path may include determining an end-to-end time delay measurement of a communication path spanning a first communication network and a second communication network, and transmitting a message comprising the determined end-to-end time delay measurement of the communication path spanning the first communication network and the second communication network to a network element of the first communication network, wherein the message is configured to enable the network element of the first communication network to configure the first communication network to provide sufficient Quality of Service (QoS) to support an end-to-end QoS requirement based on the determined end-to-end time delay.
Owner:QUALCOMM INC

A PLC system communication method and system based on a DCS redundant network

The application provides a PLC system communication method and system based on a DCS redundant network, relates to the technical field of industrial automation control system communication network integration, and comprises the following steps: network architecture reconstruction, direct access of a programmable logic controller (PLC) to a redundant industrial Ethernet of a distributed control system (DCS), and formation of a unified local area network; IP address planning, allocation of addresses of the same preset IP network segment to controllers of the DCS, PLCs, industrial personal computers and optional communication modules, and ensuring direct communication between devices; the application can save special communication modules and supporting equipment, reduce direct hardware cost, reduce cabinet space occupation and wiring cost by fully utilizing the existing redundant network infrastructure of the DCS; for a system containing multiple PLCs, the cost advantage is more obvious, no additional investment in redundant communication hardware is needed, and the overall investment is further reduced.
Owner:YANGCHUN NEW STEEL CO LTD

Crown block remote monitoring regulation and control system

The invention provides a crown block remote monitoring and regulating system, and relates to the technical field of crown blocks. The crown block remote monitoring regulation and control system comprises a crown block control system and network bridge equipment, the crown block control system is connected with the network bridge equipment, and the network bridge equipment is configured to establish communication connection with ground terminal equipment when the network bridge equipment and the ground terminal equipment are located in the same network segment. The network bridge equipment is configured to form a sight distance wireless communication path with the ground terminal equipment when the network bridge equipment is in communication connection with the ground terminal equipment; the crown block control system is used for collecting operation data of different crown block assemblies and transmitting the operation data to the ground terminal equipment through the network bridge equipment, so that the ground terminal equipment displays the operation state and fault information of the crown block assemblies in real time according to the operation data. According to the invention, errors and lagging caused by manual reading or single instrument monitoring in the prior art are avoided, and the safety and the working efficiency are greatly improved.
Owner:GUANGXI DEBAO BAIKUANG ALUMINUM CO +3

Method and system for testing optical module by using server

The invention relates to a method and system for testing optical modules by using one server, and the method comprises the following steps: connecting two optical modules to be tested, which need to be streamed, to two Ethernet ports of one server, and connecting the two optical modules to be tested, which need to be streamed, with a switch through optical fibers; aiming at two Ethernet ports connected with two to-be-tested optical modules needing streaming, two independent network namespaces are created on a server, and the two Ethernet ports are respectively distributed to the two network namespaces; allocating an IP (Internet Protocol) for a network card in each network namespace, setting default routes for the two network namespaces, respectively pointing to the IP of the logic port of the butted switch, and configuring the IP of the logic port corresponding to the switch, so that the network namespace in which each Ethernet port is located and the logic port of the butted switch are located in the same network segment; the network segments of the two network namespaces are different from each other, and the switch can forward the traffic of the two network segments; and testing the flow between the two optical modules to be tested.
Owner:WUHAN HUAGONG GENUINE OPTICS TECH CO LTD

Network segment control method and device based on sentry mode, equipment and medium

The invention relates to the technical field of network segment control, and discloses a network segment control method and device for a sentry mode, equipment and a medium, and the method comprises the steps: activating an appointed network management function group corresponding to the sentry mode through a preset network management strategy when the sentry mode of an appointed vehicle is started; after the specified network management function group is activated, determining a first network segment related electronic control unit in a CAN network and a second network segment related electronic control unit in an LIN network which need to be kept in a sentry mode; controlling a related electronic control unit of a third network segment of the CAN network to enter dormancy through the specified network management function group, wherein the third network segment is the other network segments except the first network segment in the CAN network; and controlling a related electronic control unit of a fourth network segment of the LIN network to enter dormancy through the specified network management function group, wherein the fourth network segment is the other network segment except the second network segment in the LIN network.
Owner:GREAT WALL MOTOR CO LTD

Device for autonomous detection of cyber threats

A device for the autonomous detection of cyber threats, consisting of: a housing that encloses a multitude of interconnected hardware components; a network interface unit configured to receive and send data packets from one or more communication networks; a data acquisition unit that is operationally connected to the network interface unit and configured to capture packet-level data, metadata, and system event logs; a preprocessing processor configured to analyze captured data, decodecode protocols, reconstruct communication flows, and generate structured data representations; a feature extraction processor that is operationally coupled with the preprocessing processor and is configured to calculate statistical, temporal and entropy-based features from the structured data representations; a storage unit consisting of volatile memory for real-time processing and non-volatile memory for storing historical data and learned patterns; an inference processor that is operationally coupled with the feature extraction processor and the storage unit, wherein the inference processor is configured to execute a variety of trained models to identify anomalous behavior based on deviations from stored patterns; a classification unit that is operationally coupled with the inference processor and configured to assign detected anomalies to one or more threat categories based on calculated confidence values; a response control unit configured to generate and transmit remedial actions, including blocking network traffic, isolating network segments, and terminating suspicious processes; and a control processor configured to coordinate the data flow between the network interface unit, the data acquisition unit, the preprocessing processor, the feature extraction processor, the inference processor, the classification unit, the response control unit, and the storage unit, with the device operating autonomously to detect and respond to cyber threats in real time.
Owner:ALMOMANI DUAA SHAWKAT +1

Estimation of a packet loss rate in a network segment on the uplink

Various aspects of the present disclosure generally relate to wireless communication. In some aspects, a user equipment (UE) may receive an indication of packet loss on the uplink between the UE and a network node, and may receive an indication of overall packet loss between the UE and an endpoint on the uplink (for example, a quantity of packets lost as observed by the endpoint). The UE may then compute a packet loss rate on the network segment from the network node to the endpoint using the uplink packet loss indication and the end-to-end packet loss indication. The UE may then transmit one or more packets that are to be received by the endpoint. A quantity of the one or more packets may depend on the packet loss rate. Numerous other aspects are described.
Owner:QUALCOMM INC

Network anomaly positioning method, device and equipment and readable storage medium

PendingCN122476012AAlgorithmEngineering
The application provides a network anomaly positioning method and device, equipment and a readable storage medium, relates to the technical field of communication, and is applied to an anomaly positioning device. The method comprises the following steps: obtaining a first segment characteristic value, the first segment characteristic value being a value of a transmission characteristic of a first network segment in a network; determining N segment characteristic comparison values, the N segment characteristics comprising transmission characteristics of N network segments in the network, each segment characteristic comparison value in the N segment characteristic comparison values being within a reference value range of the transmission characteristic of the corresponding segment; inputting the N segment characteristic comparison values and the first segment characteristic value into a first prediction model to obtain a first output of the first prediction model, the first prediction model being used for determining whether the network is an abnormal network based on N+1 values corresponding to N+1 segment characteristics; and determining whether the first network segment is an abnormal network segment according to the first output. The application is used for solving the problem of low positioning efficiency when positioning the network anomaly position.
Owner:HUAWEI TECH CO LTD

Equipment remote calibration access method and system for industrial isolation network

The invention discloses an equipment remote calibration access method and system for an industrial isolation network, and the method comprises the steps: scanning an operation environment of an operation and maintenance terminal, and detecting whether the operation and maintenance terminal has the capability of processing an industrial field encryption protocol; when the operation environment does not have the capability of processing the industrial field encryption protocol, automatically blocking the connection; when the operation environment has the capability of processing an industrial field encryption protocol, establishing a cross-domain simulation link and a data link sending probe; when the echoed data are consistent, calibration is allowed to be performed, otherwise, an alarm indicates that the link is unreliable. According to the equipment remote calibration access method and system for the industrial isolation network provided by the invention, the equipment in the isolation network segment can be safely calibrated and maintained by establishing the cross-domain simulation link.
Owner:NINGBO BEILUN FIRST CONTAINER TERMINAL CO LTD +1

Commercial vehicle CAN bus network topology reverse generation method and corresponding device

PendingCN121217503ABus networksEngineeringUSB
The invention discloses a CAN bus network topology reverse generation method of a commercial vehicle and a corresponding device. The method comprises the following steps: connecting a whole vehicle network of a commercial vehicle through a USB-CAN adapter, obtaining whole vehicle message information, and determining the number of network segments according to the number of OBD interfaces receiving node messages; all ECU nodes are determined and counted based on the node source address carried by each node message; if the node message of one ECU node only appears in one network segment, determining that the ECU node is configured in the network segment; if the node message appears in different network segments, determining that a gateway node exists between the different network segments, and determining the network segment to which the ECU node of the node message belongs according to the appearance time of the node message in the different network segments and the message content change and / or periodic change; and establishing a CAN bus network topology according to the determined network segment, the ECU node and the affiliation relationship. According to the invention, the message of the whole vehicle is collected, and the message is precisely, efficiently, reversely and automatically analyzed and the visual network topology is generated.
Owner:ZERON AUTOMOBILE TECHNOLOGY CO LTD

Printer management method, computer device, storage medium and program product

Disclosed in the embodiments of the present application are a printer management method, a computer device, a storage medium and a program product. The method comprises: in response to a printer search request for a target address network segment, sending a probe data packet to a network address comprised in the target address network segment; acquiring a message response to the probe data packet, and on the basis of the message response, determining a printer address; on the basis of the printer address, establishing a network connection with a target printer corresponding to the target address network segment, wherein printers comprise the target printer; and on the basis of the network connection, sending a model file to the target printer. By using the present application, the convenience of printer deployment can be improved.
Owner:SHANGHAI LUNKUO TECH CO LTD

Network asset simulation method and device based on honeypot technology, equipment and medium

The present disclosure provides a network asset simulation method and device based on honeypot technology, equipment and medium, the method comprises: obtaining the attribute information of each target network asset in the target network segment in the active state and the service information of the opened target network service; for each target network asset, based on the service information and attribute information corresponding to the target network asset, determine whether there is a target honeypot service matched with the target network service in each honeypot service pre-generated in the honeypot system; if so, bind the target network asset to the target honeypot service. By using the method, when simulating network assets, the existing honeypot services in the honeypot system can be matched with the target network services, and the existing honeypot services in the honeypot system can be directly used to simulate network assets, so that the honeypot services do not need to be created every time, thereby saving the time of simulating network assets and realizing rapid simulation.
Owner:HARBIN ANTIY TECH

Pressure feedback-based method and system for protecting and regulating water hammer of large-scale drip irrigation pipe network

PendingCN122623586ASensor arrayData set
This invention discloses a method and system for water hammer protection and control in large-scale drip irrigation networks based on pressure feedback, relating to the field of drip irrigation water hammer prevention and control technology. The method includes: constructing the drip irrigation network topology using GIS digital modeling technology and marking the locations of water hammer protection devices; collecting network water condition data through sensor arrays, and constructing a network water condition dataset after preprocessing; calculating the water hammer risk coefficient of each network segment using a covariance matrix discriminant model based on the network topology and water condition dataset, selecting a set of risky network segments, solving the pre-control action parameters of the adjustable water hammer protection device using a particle swarm optimization algorithm, and issuing the device for execution after verification through steady-state and transient joint hydraulic simulations, thereby predicting and preventing water hammer occurrence and ensuring steady-state network pressure. This invention achieves accurate identification and efficient control of water hammer risk in large-scale drip irrigation networks, reduces water hammer protection energy consumption, and ensures stable operation of large-scale drip irrigation networks.
Owner:CHINA AGRI UNIV

DNS cache optimization system based on multi-node collaboration

The invention discloses a DNS (Domain Name Server) cache optimization system based on multi-node collaboration, which is suitable for public DNS, operator recursion, CDN (Content Delivery Network) scheduling and cloud native scenes. The system is composed of an edge recursion node, a shared second-level cache layer, a cooperative forwarding and near-source rollback module, a distributed active refreshing and lease cooperation module, a cache key generation and routing module and a toughness mechanism module. The domain name and the client network segment are taken as main keys, and the ECS and the two-stage consistent Hash are combined to realize request viscosity and fragmentation stability; when a local miss occurs, preferentially forwarding to a same network segment / same city-same operator / same region collaborative node, and then returning to share cache and authority; a coordination node is elected and refreshed according to domain name fragments, active refreshing of hotspots and immediate entries is driven by lease + priority, and group frightening is avoided through push / pull diffusion; toughness capabilities such as request merging, fusing degradation, health detection and the like are provided, and automatic near-source fallback and removal of abnormities are achieved. According to the method, the hit rate and the first packet delay can be remarkably improved.
Owner:JINAN DIXUN INFORMATION TECH CO LTD

Cloud network system, communication method, device, storage medium, and program product

PCT designated stageWO2026016770A1TransmissionDomain nameIp address
Embodiments of the present disclosure provide a cloud network system, a communication method, a device, a storage medium, and a program product. A proxy node is deployed in a second cloud network, and the domain name of the proxy node is configured on a client node corresponding to a cloud service. When a client node accesses a cloud service in the second cloud network, the client node acquires the IP address of a proxy node on the basis of the domain name of the proxy node, and, on the basis of the IP address of the proxy node, forwards to the proxy node a target access request for accessing the cloud service in the second cloud network. The proxy node, on the basis of preconfigured forwarding rule information used for describing a forwarding relationship between each access request received by the proxy node and a service node in the second cloud network, forwards the target access request to a target service node providing a target cloud service, rather than forwarding the target access request to a node in a first cloud network that belongs to the same network segment as the target service node, thereby preventing network segment conflicts.
Owner:CLOUD INTELLIGENCE ASSETS HOLDING (SINGAPORE) PTE LTD +1

Fault diagnosis method and device, vehicle and computer readable storage medium

The invention provides a fault diagnosis method and device, a vehicle and a computer readable storage medium, and relates to the technical field of fault diagnosis, and the method comprises the steps: obtaining a whole vehicle power supply wire harness and a communication network topology structure; when it is detected that node loss occurs in the electronic control unit, whether a shared power supply branch or a shared communication network segment exists or not is judged based on the power supply wire harness and the communication network topological structure; if it is judged that the common power supply branch and / or the communication network segment exist, determining whether each electronic control unit shows a synchronism abnormal behavior or not; if it is judged that the common power supply branch and the communication network segment do not exist, whether each electronic control unit shows an independent abnormal behavior or not is determined; and according to the synchronization or independence abnormal behavior, selectively executing a corresponding fault diagnosis action, and generating diagnosis fault code information. According to the method, a space and time two-dimensional cross validation mechanism is adopted, comprehensive monitoring of the global signal state is achieved, and the detection comprehensiveness and the fault positioning accuracy are improved.
Owner:GREAT WALL MOTOR CO LTD

Method and device for predicting network attack path

The invention relates to a network attack path prediction method and device, and the method comprises the steps: determining a high-risk network segment based on the vulnerability characteristics of a fallen asset device and an embedded vector of each network segment in the network, which is obtained in advance, under the condition that a network attack event occurs in the network and at least one fallen asset device is generated; wherein the embedding vector of each network segment is determined by the asset equipment contained in the network segment, the corresponding relationship between the asset equipment and the node, and the embedding vector of the corresponding node; determining high-risk asset equipment in the determined high-risk network segment based on the determined vulnerability characteristics of all asset equipment in the high-risk network segment and the vulnerability characteristics of the fallen asset equipment; and obtaining a network attack path from the fallen asset equipment to the determined high-risk asset equipment. Therefore, the detection efficiency of risk asset equipment in a large-scale network environment is remarkably improved through hierarchical risk assessment.
Owner:BEIJING VENUS INFORMATION SECURITY TECH +1

A three-site mutual backup method under a commercial secret network virtualization architecture

PendingCN122340118AComplete dataStation
This invention relates to a three-site mutual backup method under a commercial encrypted network virtualization architecture, belonging to the field of network communication technology. It addresses the technical problems of existing cross-regional and cross-network segment communication schemes, including insufficient interconnection security, adaptability, data backup efficiency, fault switching response speed, hardware architecture cost-effectiveness, and incomplete scenario coverage. The method includes the following steps: master station backup generation; parallel off-site replication; breakpoint resumption and anomaly recovery; local storage and version retention at branch stations; fault switching and local recovery. The three-site mutual backup method under the commercial encrypted network virtualization architecture of this invention offers: superior interconnection security and adaptability, more efficient and complete data backup, low-impact automated fault switching, a more reasonable and cost-controllable hardware architecture, higher detection accuracy, and stronger scalability.
Owner:CHANGCHUN INST OF OPTICS FINE MECHANICS & PHYSICS CHINESE ACAD OF SCI