Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

142 results about "Penetration test" patented technology

A penetration test, colloquially known as a pen test, pentest or ethical hacking, is an authorized simulated cyberattack on a computer system, performed to evaluate the security of the system. The test is performed to identify both weaknesses (also referred to as vulnerabilities), including the potential for unauthorized parties to gain access to the system's features and data, as well as strengths, enabling a full risk assessment to be completed.

Penetration test automation method and device based on large language model and ATTCK framework

The invention discloses a method based on a large language model and ATTamp; the invention discloses a CK framework penetration test automation method and device, and the method comprises the steps: firstly carrying out the structural analysis of multi-source input information and tool output, and guaranteeing that key fields are not discarded; then combining a retrieval enhancement generation technology and a network security knowledge base to provide domain knowledge support for the large language model, so as to generate a model with ATTamp; a penetration test task tree marked by CK tactics, technologies and sub-technologies; on the basis, an optimal tool is automatically selected through a tool resource library and a multi-dimensional screening mechanism, an execution instruction is generated, and finally an execution result is returned to the input analysis module to form a self-adaptive optimization test closed loop. According to the method, semantic fidelity compression and standardization processing of long information can be realized aiming at the problems of large output format difference, more information redundancy and the like of different penetration testing tools, and efficient, explainable and auditory technical support can be provided for automatic penetration testing in a complex network environment.
Owner:GUANGZHOU UNIVERSITY

Penetration testing method and device based on large language model

The invention discloses a penetration test method and device based on a large language model, and the method comprises the steps: carrying out the analysis processing of input data according to the type of the obtained input data, and obtaining a penetration test target; the penetration test target comprises a user test target, first structured key information, second structured key information and an analysis result; based on the penetration test target, reasoning by constructing a penetration test task tree to obtain an optimized sub-task; the execution terminal executes the command to carry out penetration test to obtain a penetration test result; the terminal execution command is obtained by converting the preferable subtask. According to the invention, an automatic penetration test process driven by multi-source input data analysis and task reasoning can be realized, and the intelligent level and test efficiency of penetration test are improved.
Owner:ELECTRIC POWER RESEARCH INSTITUTE OF STATE GRID JIBEI ELECTRIC POWER CO LTD +1

Self-adaptive penetration testing method and system based on reinforcement learning

The invention relates to the technical field of network security, in particular to an adaptive penetration test method and system based on reinforcement learning, and the method comprises the steps: constructing a state space model, defining an action space, designing a reward function, optimizing a strategy model, and analyzing a test result. According to the method, a reinforcement learning mechanism is combined with target environment feedback, so that multi-step attack path planning and adaptive strategy adjustment are realized, and the intelligence and coverage depth of penetration testing are remarkably improved. And meanwhile, through backtracking analysis of the state transition sequence, the potential threat path is comprehensively identified, and accurate guidance is provided for security protection.
Owner:WUHAN MINGHE YONGAN TECH CO LTD

Penetration testing method and system based on multi-source data association and risk aggregation

PendingCN121814444ASecuring communicationRisk quantificationCritical information infrastructure
The invention provides a penetration testing method and system based on multi-source data association and risk aggregation, and the method comprises the steps: firstly carrying out the automatic collection and normalization processing of heterogeneous security data from penetration testing, source code detection, vulnerability scanning and the like, and breaking an information island; and intelligent association and attack path discovery are carried out on discrete vulnerabilities based on an attack chain model, and a dynamic risk quantification model fusing a business influence weight and attack path complexity is innovatively introduced to carry out comprehensive risk assessment. According to the technical scheme, the problems of data splitting, single analysis dimension and disjunction between risk assessment and services of a traditional scheme are effectively solved, accurate identification and quantitative grading of composite attack chain risks are finally achieved, the safety analysis operation efficiency is remarkably improved, expert knowledge is solidified in the system, and the safety analysis efficiency is improved. And a visual and reliable data support is provided for safety investment decision-making of key information infrastructure industries such as power generation and the like.
Owner:XIAN THERMAL POWER RES INST CO LTD +1

Automatic penetration test path planning method and system based on agent collaboration

The invention discloses an automatic penetration test path planning method and system based on agent collaboration, and relates to the technical field of network security. Performing initialization starting on the plurality of intelligent agents based on the penetration test target range; collecting the target system and writing the target system into a shared blackboard mechanism; matching the asset feature information with a preset vulnerability knowledge base according to the test strategy mode to generate vulnerability utilization conditions, and constructing a global attack graph according to the asset feature information and the vulnerability utilization conditions; generating an attack path based on the global attack map, executing an attack operation on the target system according to an attack step sequence of the attack path, when an execution result is failure, updating the global attack map according to a feedback failure result, and re-planning to generate a new attack step sequence; and when the execution result is successful, generating a penetration test report for the penetration test target range according to the success result. By implementing the method, the actual demand of deep security assessment of the complex heterogeneous system is met.
Owner:BEIJING YUHONG XINAN TECHNOLOGY CO LTD

Penetration testing apparatus

To provide a penetration testing device applicable even to a low-strength improved ground.SOLUTION: A penetration test device 4 for performing a penetration test on a hole wall 21 of a measurement hole 2 in the measurement hole 2 includes a penetration body holding means 44 for holding a penetration body, a slide mechanism 46 for moving the penetration body holding means 44 toward and away from the hole wall 21 of the measurement hole 2, and a measuring means 45 for measuring a penetration resistance force when the penetration body penetrates the hole wall 21.SELECTED DRAWING: Figure 5
Owner:TAISEI CORP

A multi-level quantitative evaluation method for an electronic product information clearing, verifying and tracing credible closed loop system

PendingCN122346411ATechnology developmentAttack
The application discloses a kind of multi-level quantitative evaluation methods for electronic product information clearing, verification and traceable credible closed-loop system, comprising S100, evaluation framework establishment and test environment preparation step: S110, define evaluation model, the evaluation model includes clearing effect layer (L1), verification credible layer (L2), trace and authentication layer (L3), system behavior and security layer (L4) and performance and efficiency layer (L5).The application has the advantages that: from qualitative to quantitative: a large number of quantitative indicators such as KL divergence, bit recovery rate, throughput are introduced, and the evaluation results are objective, accurate and comparable.The method carries out deep security testing: not only test function, but also take the system itself as attack target, carry out penetration testing and process behavior monitoring, can find deeply hidden design defects and security vulnerabilities, which cannot be achieved by traditional function testing.At the same time, the method can guide technology development, and provide decision basis for procurement and supervision;And high automation and repeatability.
Owner:GUIZHOU UNIV

Permeation test effect evaluation method and system based on attack mode framework

The invention relates to the technical field of information security, in particular to a penetration test effect evaluation method and system based on an attack mode framework, and the method comprises the steps: firstly, constructing an evaluation model comprising a target layer, a criterion layer and an index layer; the evaluation indexes under each criterion are weighted through a large language model, and the indexes are quantitatively scored by experts. And for each criterion, on the basis of a grey theory, calculating a comprehensive evaluation vector of the criterion by using index scores, weights, a preset comment set and a whitening weight function so as to obtain a quantitative score and a qualitative evaluation result. And finally, calculating a final comprehensive evaluation result of the target layer by integrating the quantitative score vectors and the criterion weights of all the criteria. During decision making, the final result needs to be combined with the qualitative evaluation conclusion of each criterion so as to formulate a comprehensive and targeted security reinforcement strategy. According to the invention, the accuracy of penetration test effect evaluation is improved.
Owner:AIR FORCE UNIV PLA

A multi-model cooperative penetration testing method, device and electronic equipment

A multi-model cooperative penetration testing method, device and electronic equipment, relating to the field of data processing. In the method, target asset information and external knowledge data of a target system are obtained, the target system being an object to be penetrated; the target asset information is analyzed in combination with the external knowledge data to obtain corresponding structured penetration data; the current state of the target system is obtained, and the current state and the structured penetration data are input into a preset large language model to generate a penetration testing strategy; based on the penetration testing strategy, a preset reinforcement learning algorithm is used to generate an attack path; the original attack code corresponding to the attack path is input into a preset generative adversarial network to generate obfuscated attack code; and based on the attack path and the obfuscated attack code, the target system is penetrated to obtain a penetration testing result. The technical solution provided by the present application improves the penetration testing coverage.
Owner:BEIJING TIANFANG SECURITY TECH CO LTD

Contextual weakness scoring during network penetration testing

An autonomous pentesting agent may execute an autonomous pentest of a network including a first network asset and additional network assets that are downstream from the first network asset within attack paths of the autonomous pentest. The autonomous pentesting agent may gain unauthorized access to the first network asset, and, based on accessing the first network asset, gain unauthorized access to the additional network assets. The autonomous pentesting agent may generate, as part of the autonomous pentest, scores for the first network asset and the additional network assets. A first score for the first network asset may be based on a first weakness score of the first network asset and on additional weakness scores corresponding to the additional network assets that are downstream from the first network asset. The autonomous pentesting agent may output, based on the autonomous pentest, a ranking of network assets based on the scores.
Owner:HORIZON 3 AI INC

Security test method and device for industrial real-time database and storage medium

The invention discloses a security test method and device for an industrial real-time database and a storage medium, and relates to the technical field of industrial internet. The method comprises the following steps: based on a three-security partition architecture, realizing security test on the industrial real-time database by verifying the transmission security of each interval. The logic isolation test between the first security zone and the second security zone emphatically checks access control strategies, industrial protocol transmission integrity and abnormal traffic filtering. The physical isolation test between the first security area or the second security area and the third security area comprises the steps of verifying one-way transmission and data integrity of the forward isolation device and verifying formats and security policies by the reverse isolation device. The cross-three-zone linkage transmission test covers end-to-end data transmission security verification, a simulation attack penetration test from a third security zone to a first security zone, and an emergency mechanism test under an isolation device fault. According to the method, the safety of the industrial real-time database can be improved through a three-partition testing method.
Owner:CHINA IND INTERNET RES INST

A method and system for mining privilege-related vulnerabilities in power monitoring systems

PendingCN122339727AData packData set
This invention discloses a method and system for mining permission-related vulnerabilities in power monitoring systems. First, it automates login to the target system to obtain valid test sessions. Then, it simulates user operations to trigger system function interfaces, capturing network request data during the interaction process and constructing an interface dataset. Data packets are filtered and analyzed, and sensitive traffic with abnormal permissions is identified based on a large language model. Cookies are replaced and replay tests are performed. The original response and the replay response are compared, and the presence of horizontal privilege escalation vulnerabilities is determined by calculating structural similarity. This invention effectively overcomes the shortcomings of traditional automated tools, such as high false positives and false negatives and poor flexibility due to a lack of dynamic decision-making capabilities, by constructing a complete closed-loop process of automated login, interface data collection, intelligent identification using a large language model, and cookie replacement and replay. This significantly improves the intelligence level of penetration testing and the accuracy of vulnerability mining.
Owner:NARI INFORMATION & COMM TECH

Password guessing method based on multi semantic fusion probability context-free grammar

ActiveCN121479754BMathematical modelsSemantic analysisPassword policyPassword
The present application relates to the technical field of information security, and aims at the problems that password guessing based on probabilistic context-free grammar is difficult to identify multi-semantic patterns and the semantic guidance strength is uncontrollable, and proposes a password guessing method based on multi-semantic fusion of probabilistic context-free grammar: enumerating sub-strings in the training password, identifying semantic segments according to simple, date, vocabulary and name patterns and prioritizing disambiguation, dynamically planning segmentation according to the principle of maximum semantic coverage and least semantic segments, setting semantic enhancement parameters β for each semantic pattern during training to weight and normalize the count, and outputting the candidate password dictionary according to the probability priority queue during generation, which is suitable for efficient password guessing in offline password audit, password policy evaluation and penetration testing.
Owner:NANKAI UNIV

Penetration testing method and system for mobile application of swan gap system

The invention relates to a penetration test method and system for mobile applications of a swan monk system, and the method comprises the steps: obtaining a current version installation package, extracting static asset data, and capturing dynamic behavior data; constructing a threat model for the gap distributed architecture; generating a penetration test case set through the threat model, and deploying and executing the penetration test case set; inputting the heterogeneous security telemetry data into the risk identification model, and executing a preset corresponding processing strategy; generating a penetration test report based on the risk judgment information and the execution result of the processing strategy; in conclusion, according to the penetration testing method and system for the mobile application of the swan-mong system, the threat model for the swan-mong distributed architecture is constructed, and the dynamic stain tracking and fuzzy testing technology is integrated, so that the cross-equipment safety risk is systematically detected; the method has the effects of effectively identifying the cross-equipment security threats in the swan-gap distributed architecture and improving the comprehensiveness and accuracy of the penetration test.
Owner:HONGMENG ECOLOGICAL SERVICES (SHENZHEN) CO LTD

Satellite-borne computer penetration test method and system

The invention provides a spaceborne computer penetration test method and system, and the method comprises the steps: carrying out the recognition and analysis of a physical layer protocol, a link layer protocol, a transmission layer protocol and an application layer protocol related to a target spaceborne computer, and completing the communication of a communication link and the mapping of a protocol field; designing and generating multiple types of attack loads based on a protocol and a functional model, and injecting multiple attack data packets in intranet penetration, transverse movement, flooding attack and instruction rearrangement; multiple operation indexes, state parameters and abnormal events of the spaceborne computer are collected in real time, and data processing and feature extraction are carried out; setting a multi-dimensional anomaly criterion and a scoring model, carrying out the discrimination and quantification of the anomaly indexes, and outputting a risk level; and according to the attack input, the abnormal response and the scoring result, carrying out grading risk judgment, and outputting a safety short board and a rectification suggestion. The method is suitable for the fields of satellite-borne computer ground testing, on-orbit evaluation and related safety protection, and the safety guarantee capability of a satellite system is improved.
Owner:SHANGHAI JIAOTONG UNIV +1

Automated penetration testing method, apparatus, device, and storage medium

The application relates to the technical field of network security, and discloses an automatic penetration testing method, device, equipment and storage medium, the method comprising the following steps: collecting executable attack codes, and generating an attack weapon library based on the executable attack codes; inputting real network information corresponding to a real network environment into an automatic penetration testing decision model to obtain real attack sub-actions, wherein the automatic penetration testing decision model is a model obtained by training an initial penetration testing model based on deep reinforcement learning technology; and performing automatic penetration testing on the real network environment based on the attack weapon library and the real attack sub-actions. Since the automatic penetration testing decision model is used to obtain real attack sub-actions suitable for the real network environment, and the real attack sub-actions and the executable attack codes in the attack weapon library are combined to perform penetration testing on the real network environment, the network environment can be quickly and accurately subjected to automatic penetration testing.
Owner:UNIV OF ELECTRONICS SCI & TECH OF CHINA +1

Penetration testing method, device and equipment based on mobile equipment

The invention provides a penetration testing method, device and equipment based on mobile equipment, is applied to the field of penetration testing of mobile terminals, and is used for solving the problems of poor stability and high security risk of the mobile equipment caused by a penetration testing method depending on a real root authority. The method is applied to a mobile device installed with a simulator application, the simulator application provides a virtual operation environment for simulating an operation system and has a virtual root permission of the virtual operation environment, and the method comprises the following steps: importing and analyzing an installation file of a to-be-tested application in the virtual operation environment through the simulator application, obtaining a configuration parameter set used when the to-be-tested application normally runs in the operating system, creating a test sub-process of the test host process, calling the test sub-process, and running the to-be-tested application based on the configuration parameter set; and through the simulator application, in the running process of the to-be-tested application, based on the virtual root permission, adopting a preset penetration test strategy to execute a simulation penetration attack on the to-be-tested application.
Owner:CHINA CONSTRUCTION BANK +1

System and method configured to perform penetration testing of virtual reality systems using machine learning

A system and method perform penetration testing of virtual reality (VR) systems using machine learning. A machine learning module receives VR system parameters of the VR system, identifies characteristics of the VR system from the VR system parameters thereby identifying the VR system, and performs a VR vendor-specific penetration test corresponding to the identified characteristics, thereby generating penetration test results associated with the VR system. A report generating module generates and outputs an assessment report of the VR system using the penetration test results. The method implements the system.
Owner:SAUDI ARABIAN OIL CO

Network penetration and planning method and system based on artificial intelligence

The invention provides a network penetration and planning method and system based on artificial intelligence, and relates to the field of network security, and the method comprises the steps: collecting network topology and host port data, recognizing known and unknown script vulnerabilities, constructing a vulnerability knowledge graph, and generating a penetration link; generating an attack view on the three-dimensional interface; generating a technology and behavior permeation chain and an execution sequence according to the target node; and finally, respectively generating attack instructions or codes for different types of vulnerabilities, and outputting a protection strategy. According to the method, the automation degree of penetration testing is improved, the unknown vulnerability discovery capability is enhanced, and the attack and defense resource configuration is optimized.
Owner:JIANGSU BOZHI SOFTWARE TECH CO LTD

linker

ActiveCN309870068SAir conditioningBiology
1. The name of the design product: joint. 2. The use of the design product: used for air conditioning pipe penetration test integrated joint. 3. The design points of the design product: in shape. 4. The picture or photo that best indicates the design points: perspective view.
Owner:TIANJIN PENGYI GRP CO LTD

Multi-step vulnerability utilization chain automatic generation method and device based on knowledge graph

The invention discloses a multi-step vulnerability utilization chain automatic generation method and device based on a knowledge graph, and belongs to the technical field of combination of cyberspace security and artificial intelligence. The implementation method comprises the following steps: 1, constructing a vulnerability knowledge graph; 2, performing full-text indexing and graph traversal on the vulnerability knowledge graph to obtain a structured context; 3, the Qwen3coder model constructs a penetration test spanning tree in the form of a tree structure by using the dependency relationship between penetration steps and hierarchical nodes, and obtains the current penetration test spanning tree state; 4, executing the analysis agent, the planning agent, the command generation agent, the execution agent and the evaluation agent in sequence in a circulation mode, and generating a complete vulnerability utilization chain plan; and 5, generating a penetration test report for defense by utilizing a Qwen3coder model based on vulnerability utilization chain planning. Compared with the prior art, in a complex network environment, automatic planning of a multi-step vulnerability utilization chain is achieved, and then vulnerability utilization defense is completed.
Owner:BEIJING INST OF TECH

Security left shift research and development and operation method and device

PendingCN121996204ASoftware designPlatform integrity maintainanceSoftware development processLogisim
The invention discloses a research, development and operation method and device for security left shift, and relates to the field of software development processes and security management.The method comprises the steps that a security demand baseline is established in the demand analysis stage, security demands and business demands are fused, and risk protection measures are determined; security architecture design review is carried out in the architecture design stage, and a security team carries out threat modeling on the system architecture and carries out one-ticket negative right; in the code development stage, code specifications, open source component vulnerabilities and logic risks are scanned in real time through a static code analysis tool, and a code security closed-loop management mechanism is established; in the compiling and constructing stage, code review and component list filing are implemented, a security review report is formed by combining a dynamic penetration test and a running flow test, and a security strategy is updated through a continuous monitoring mechanism to deal with new threats. Security practice can be systematically integrated in the early stage of the software development life cycle, and the later vulnerability repair cost is remarkably reduced.
Owner:CHINA CONSTR BANK CORP

An Automated Penetration Testing Method Based on Reinforcement Learning

ActiveCN119449373BImprove work efficiencyImprove the effectiveness of intelligent penetration testingBiological modelsSecuring communicationEngineeringData mining
This invention relates to an automated penetration testing method based on reinforcement learning, belonging to the field of cyberspace security in computer and information science and technology. First, this invention utilizes environment-related parameters to construct the state space, action space, and reward function of the reinforcement learning model to generate training data. Second, it applies the training data and vulnerability exploitation components to train and generate a reinforcement learning model. Finally, based on a vulnerability exploitation component library, the reinforcement learning model recommends optimal vulnerability exploitation information, thereby automating the entire penetration testing process. This invention addresses the problems of manual reliance in penetration testing and the rigid application of vulnerability exploitation components by employing artificial intelligence technology to effectively improve the accuracy of vulnerability exploitation component recommendations, significantly enhancing the efficiency of penetration testing.
Owner:BEIJING INST OF TECH

A device and method for measuring three-dimensional deformation field of a projectile body in a penetration process

The application discloses a kind of three-dimensional deformation field measuring device and measuring method of projectile body in penetration process, it is related to projectile body penetration test technical field, its technical solution key points are: including: light gas gun, for launching solid projectile;Special target store, its lateral wall is equipped with observation window, inside is equipped with target plate and the projectile to be measured fixed on target plate;Three-dimensional digital image acquisition equipment, symmetrically arranged outside observation window, including two high-speed cameras of synchronous trigger, matching lens, high-brightness light source and synchronous trigger;Magnetic speed measuring instrument, set in the tail of the barrel of light gas gun;Data processing equipment is used to receive the image sequence collected by three-dimensional digital image acquisition equipment, based on calibration parameter calculation the three-dimensional displacement field of the surface of the projectile to be measured, full-field strain field and velocity field, visual output deformation evolution process.The application can realize the non-contact, high space-time resolution measurement of three-dimensional dynamic deformation field of projectile body itself in the transient process of projectile body penetrating target plate.
Owner:BEIJING INST OF TECH

AI-combined front-end js code intelligent analysis method and system based on penetration test

The invention discloses an AI-combined front-end js code intelligent analysis method and system based on penetration testing, belongs to the technical field of artificial intelligence and penetration testing, and aims to solve the technical problem of how to realize AI-driven front-end penetration testing, improve the penetration testing efficiency, coverage and depth and improve the reliability of the penetration testing. According to the technical scheme, the method comprises the steps of intelligent attack surface surveying and mapping, wherein the structure and the function of a target application are fully perceived through an intelligent crawler, static code analysis and AST; wherein the intelligent crawler is a data acquisition tool combined with an artificial intelligence technology; according to static code analysis, the structure of the intelligent crawler is further analyzed, front-end JavaScript codes are analyzed into AST, the AST is structured representation of the codes, the AI understands the logic structure of the codes through the AST, and data flow tracking is carried out more accurately. Performing reverse analysis on the intelligent front-end code; and performing automatic vulnerability identification and attack simulation.
Owner:INSPUR QILU SOFTWARE IND

Spaceborne Computer Penetration Testing Methods and Systems

ActiveCN121356917BData packAttack
This invention provides a method and system for penetrating spaceborne computers, comprising: identifying and parsing the physical layer, link layer, transport layer, and application layer protocols involved in the target spaceborne computer, completing communication link connectivity and protocol field mapping; designing and generating multiple types of attack payloads based on protocol and functional models, injecting various attack data packets including internal network penetration, lateral movement, flooding attacks, and command replay; real-time collection of multiple operational indicators, status parameters, and abnormal events of the spaceborne computer, performing data processing and feature extraction; setting multi-dimensional anomaly criteria and scoring models, identifying and quantifying abnormal indicators, and outputting risk levels; and performing graded risk assessment based on attack input, abnormal responses, and scoring results, outputting security vulnerabilities and rectification suggestions. This invention is applicable to ground testing, on-orbit evaluation, and related security protection fields of spaceborne computers, improving the security assurance capabilities of satellite systems.
Owner:SHANGHAI JIAOTONG UNIV +1

Rag and multi-agent based business logic vulnerability automatic penetration testing method

This invention relates to the field of network security technology, and in particular to an automated penetration testing method for business logic vulnerabilities based on RAG and multi-agent systems. The method includes: Step S1, performing deep perception and dynamic knowledge fusion on the test target; Step S2, intelligent planning of the vulnerability knowledge package; Step S3, formulating a parallel test plan for the test step sequence; Step S4, executing the parallel test plan in parallel; Step S5, performing collaborative monitoring; Step S6, performing multi-dimensional analysis and confidence quantification; Step S7, performing recursive optimization to obtain a test step sub-sequence; Step S8, dynamically adjusting the test step sub-sequence based on constraint checks; and Step S9, accumulating and evolving the knowledge of the entire automated penetration testing process. This invention improves the detection accuracy, automation level, optimization capability, and efficiency of parallel multi-vulnerability detection in network security technology.
Owner:BEIJING ANJIHUI TECHNOLOGY CO LTD