Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

219 results about "Penetration test" patented technology

A penetration test, colloquially known as a pen test, pentest or ethical hacking, is an authorized simulated cyberattack on a computer system, performed to evaluate the security of the system. The test is performed to identify both weaknesses (also referred to as vulnerabilities), including the potential for unauthorized parties to gain access to the system's features and data, as well as strengths, enabling a full risk assessment to be completed.

Penetration test automation method and device based on large language model and ATTCK framework

The invention discloses a method based on a large language model and ATTamp; the invention discloses a CK framework penetration test automation method and device, and the method comprises the steps: firstly carrying out the structural analysis of multi-source input information and tool output, and guaranteeing that key fields are not discarded; then combining a retrieval enhancement generation technology and a network security knowledge base to provide domain knowledge support for the large language model, so as to generate a model with ATTamp; a penetration test task tree marked by CK tactics, technologies and sub-technologies; on the basis, an optimal tool is automatically selected through a tool resource library and a multi-dimensional screening mechanism, an execution instruction is generated, and finally an execution result is returned to the input analysis module to form a self-adaptive optimization test closed loop. According to the method, semantic fidelity compression and standardization processing of long information can be realized aiming at the problems of large output format difference, more information redundancy and the like of different penetration testing tools, and efficient, explainable and auditory technical support can be provided for automatic penetration testing in a complex network environment.
Owner:GUANGZHOU UNIVERSITY

Web automatic penetration testing method and device, electronic equipment and storage medium

The invention provides a Web automatic penetration test method and device, electronic equipment and a storage medium, and belongs to the technical field of website vulnerability tests.The method comprises the steps that a web crawler collects target Web information to form a basic set; detecting vulnerability acquisition information; matching the adaptive script, and generating an intelligent load to verify vulnerability availability; constructing a knowledge graph to determine vulnerability association, and evaluating success rate and risk; planning an optimal attack route by using reinforcement learning, and determining attack depth and range, namely attack path risk features; and evaluating the risk by the dynamic scoring model, and generating a visual report containing detailed information, results and repair and improvement suggestions. According to the automatic penetration testing method, manual intervention is reduced in the whole process, dependence on professional experience is reduced, efficiency is improved, and the problems that traditional testing is tedious and low in efficiency are solved.
Owner:SICHUAN BANWOHUI TECHNOLOGY CO LTD +1

Multi-model collaborative penetration testing method and device and electronic equipment

The invention discloses a multi-model collaborative penetration testing method and device and electronic equipment, and relates to the field of data processing. In the method, target asset information and external knowledge data of a target system are obtained, and the target system is a to-be-permeated test object; analyzing the target asset information in combination with external knowledge data to obtain corresponding structured penetration data; obtaining the current state of the target system, inputting the current state and the structured penetration data into a preset large language model, and generating a penetration test strategy; based on the penetration test strategy, adopting a preset reinforcement learning algorithm to generate an attack path; the attack path corresponds to the original; inputting the attack code into a preset generative adversarial network to generate a confusion attack code; and performing penetration test on the target system based on the attack path and the obfuscated attack code to obtain a penetration test result. By implementing the technical scheme provided by the invention, the penetration test coverage rate is improved.
Owner:BEIJING TIANFANG SECURITY TECH CO LTD

Graph-driven self-attention compressible memory management method

The invention discloses a graph-driven self-attention compressible memory management method, and belongs to the technical field of penetration testing. According to the graph-driven self-attention compressible memory management method, an attention graph is constructed, semantic dependence and attention flow directions among multiple Agent nodes are accurately described by utilizing edge weights, the relevance and the accessibility of information are improved, and in the aspects of screening and loading, the expandability of the memory is improved. According to the method, key memory fragments are screened on the basis of concerned graph edge weights and task related features, only the loaded information is loaded, redundancy is effectively eliminated, the data volume processed by a system is reduced, and the system operation efficiency is improved; the semantic compression module can perform abstract processing on historical information based on various elements, and on the premise of ensuring that key semantic information is not lost, the abstract length is controlled within the window limit, so that the model can normally process information, and the adaptability and stability of the system to different data volumes are improved.
Owner:LIQUAN TECHNOLOGY (CHENGDU) CO LTD

System and Method for Automated Penetration Testing and Security Assessment

PendingUS20250343818A1Securing communicationAttackSocial engineering (security)
A system for automated penetration testing using artificial intelligence (AI) is described, which aims to enhance cybersecurity by simulating attacks on software and computer systems in order to measure and identify vulnerability. The platform employs AI agents to perform tasks including script execution for vulnerability testing, social engineering simulations, comprehensive security assessments, and more, thereby reducing costs, time, potential risks associated with traditional penetration testing methods, and providing a more complete and available solution than humans can produce alone.
Owner:IMMESOETE CAMERON

Timing sequence post-synchronization quantum key extraction method based on classical information fusion

A time sequence post-synchronization quantum key extraction penetration test method comprises the following steps: A) under the condition of penetration test, a QKD system operates normally, and a sending end and a receiving end smoothly complete key distribution; b) the man-in-the-middle selects an initial original key exchange period to establish synchronization and correlation so as to realize clock synchronization with a receiver; c) analyzing quantum bit error rate information obtained from a public channel by a man-in-the-middle, deducing a corresponding relation between a receiver detector and each quantum state, and establishing a mapping model of the quantum states and bit values; d) determining a quantum state type responded by the receiver in each response time slot in a subsequent original key exchange period by the middleman in combination with path information obtained by other sub penetration tests; and E) the intermediary obtains a final key which is the same as the two communication parties by implementing an error correction and privacy amplification process, the quantum bit error rate between the intermediary and the sender is maintained at a relatively low level and is lower than a security threshold, and a security alarm is not triggered in a penetration test process.
Owner:NAT UNIV OF DEFENSE TECH

Full-automatic penetration testing method based on large language model

The invention discloses a full-automatic penetration testing method based on a large language model, and relates to the field of network security. The method comprises the following six core steps: 1) constructing a host asset model through multi-source data acquisition, integrating Shodan, Fofa and eagle map platform data, and performing LLM verification; 2) calling an NVD database to identify vulnerabilities, and secondarily verifying CVE validity by using LLM; 3) dynamically disassembling the penetration task based on a collaborative penetration decision tree (SPDT), and fusing ATTamp; guiding task planning by a CK technology and tactics map; (4) a multi-agent engine is adopted to execute a command, three interaction modes of Browser-use / CLI / GUI are supported, a Kali virtual machine is connected through an SSH to execute command line operation, and a graphical tool is driven based on a multi-mode model; according to the method, the problem that the automation degree of traditional penetration testing is low is solved, and the full-process automation of the penetration testing is achieved.
Owner:SICHUAN UNIV

Penetration testing method and device based on large language model

The invention discloses a penetration test method and device based on a large language model, and the method comprises the steps: carrying out the analysis processing of input data according to the type of the obtained input data, and obtaining a penetration test target; the penetration test target comprises a user test target, first structured key information, second structured key information and an analysis result; based on the penetration test target, reasoning by constructing a penetration test task tree to obtain an optimized sub-task; the execution terminal executes the command to carry out penetration test to obtain a penetration test result; the terminal execution command is obtained by converting the preferable subtask. According to the invention, an automatic penetration test process driven by multi-source input data analysis and task reasoning can be realized, and the intelligent level and test efficiency of penetration test are improved.
Owner:ELECTRIC POWER RESEARCH INSTITUTE OF STATE GRID JIBEI ELECTRIC POWER CO LTD +1

Self-adaptive penetration testing method and system based on reinforcement learning

The invention relates to the technical field of network security, in particular to an adaptive penetration test method and system based on reinforcement learning, and the method comprises the steps: constructing a state space model, defining an action space, designing a reward function, optimizing a strategy model, and analyzing a test result. According to the method, a reinforcement learning mechanism is combined with target environment feedback, so that multi-step attack path planning and adaptive strategy adjustment are realized, and the intelligence and coverage depth of penetration testing are remarkably improved. And meanwhile, through backtracking analysis of the state transition sequence, the potential threat path is comprehensively identified, and accurate guidance is provided for security protection.
Owner:WUHAN MINGHE YONGAN TECH CO LTD

Penetration testing method and device, electronic equipment, storage medium and program product

The invention provides a penetration test method and device, electronic equipment, a storage medium and a program product, relates to the technical field of computers, and is used for improving penetration test efficiency. The method comprises the steps of obtaining a network topological graph of a target system, and then generating an attack graph of the target system based on the network topological graph and vulnerability information of each node in the target system; the attack income of each attack path in the attack graph is calculated, and a target attack path with the maximum attack income is obtained; and performing penetration testing based on the target attack path.
Owner:CHINA UNITED NETWORK COMM GRP CO LTD

Simulation attack system and method based on multiple agents and electronic equipment

The embodiment of the invention provides a multi-agent-based attack simulation system and method and electronic equipment, and the system comprises an asset detection agent which is used for processing obtained server-side data so as to generate structured environment summary information; the retrieval agent communicates with the asset agent and is used for receiving the environment summary information sent by the asset detection agent, matching known vulnerability information based on the environment summary information and generating a vulnerability utilization execution plan; the execution agent communicates with the retrieval agent and is used for simulating an attack by utilizing an execution plan based on the received vulnerability in the target environment and determining a vulnerability processing result; and the report agent is used for generating a simulation attack report based on the vulnerability processing result and displaying the simulation attack report. According to the technical scheme, the intelligent agents based on various processing functions cooperatively process the penetration testing process, intelligent decision making of penetration testing is achieved, the task processing efficiency and accuracy are improved, manual screening is reduced, and the system maintenance and development cost is reduced.
Owner:CHINA POST INFORMATION TECH (BEIJING CO LTD

Method, equipment, medium and product for tracing attacker in network security penetration test

The invention discloses an attacker tracing method, device, equipment, medium and product in a network security penetration test, and the method comprises the steps: firstly building a session connection between a client and a target system when the penetration test is started; after the session is established, the client synchronously creates a unique traceability identifier when generating an attack load, and embeds the unique traceability identifier as a digital watermark into the attack load to form load watermark data; constructing a network data packet based on the data and sending the network data packet to a target system through a session channel; carrying out distributed credible storage on attack behavior logs generated in the penetration process by adopting a preset consensus mechanism; after the test is finished, the stored log data is automatically aggregated, an electronic evidence packet meeting judicial requirements is generated, and the whole penetration test process is completely recorded, the technical scheme of the embodiment of the invention can effectively prevent the denial behavior of an attacker, ensure the traceability of the penetration test process, and significantly improve the credibility and legal potency of evidence collection after the event.
Owner:INDUSTRIAL AND COMMERCIAL BANK OF CHINA

Network security penetration test platform

The invention belongs to the technical field of network security, and particularly relates to a network security penetration test platform which comprises a data acquisition layer, a data analysis layer, a vulnerability utilization layer, a report generation layer and a user interaction layer. And comprehensive penetration testing of network security in a supply chain attack scene is realized. Potential vulnerabilities of all links of the supply chain can be accurately mined, real attack evaluation vulnerability is simulated, a targeted security protection scheme is provided for enterprises, the security protection capability of the enterprise supply chain network is effectively improved, and the problems that an existing penetration test platform is insufficient in supply chain attack coverage, low in vulnerability mining efficiency and the like are solved.
Owner:JIANGXI DIGITAL NETWORK INFORMATION SECURITY TECH CO LTD

Penetration testing method and system based on multi-source data association and risk aggregation

PendingCN121814444ASecuring communicationRisk quantificationCritical information infrastructure
The invention provides a penetration testing method and system based on multi-source data association and risk aggregation, and the method comprises the steps: firstly carrying out the automatic collection and normalization processing of heterogeneous security data from penetration testing, source code detection, vulnerability scanning and the like, and breaking an information island; and intelligent association and attack path discovery are carried out on discrete vulnerabilities based on an attack chain model, and a dynamic risk quantification model fusing a business influence weight and attack path complexity is innovatively introduced to carry out comprehensive risk assessment. According to the technical scheme, the problems of data splitting, single analysis dimension and disjunction between risk assessment and services of a traditional scheme are effectively solved, accurate identification and quantitative grading of composite attack chain risks are finally achieved, the safety analysis operation efficiency is remarkably improved, expert knowledge is solidified in the system, and the safety analysis efficiency is improved. And a visual and reliable data support is provided for safety investment decision-making of key information infrastructure industries such as power generation and the like.
Owner:XIAN THERMAL POWER RES INST CO LTD +1

Automatic penetration test path planning method and system based on agent collaboration

The invention discloses an automatic penetration test path planning method and system based on agent collaboration, and relates to the technical field of network security. Performing initialization starting on the plurality of intelligent agents based on the penetration test target range; collecting the target system and writing the target system into a shared blackboard mechanism; matching the asset feature information with a preset vulnerability knowledge base according to the test strategy mode to generate vulnerability utilization conditions, and constructing a global attack graph according to the asset feature information and the vulnerability utilization conditions; generating an attack path based on the global attack map, executing an attack operation on the target system according to an attack step sequence of the attack path, when an execution result is failure, updating the global attack map according to a feedback failure result, and re-planning to generate a new attack step sequence; and when the execution result is successful, generating a penetration test report for the penetration test target range according to the success result. By implementing the method, the actual demand of deep security assessment of the complex heterogeneous system is met.
Owner:BEIJING YUHONG XINAN TECHNOLOGY CO LTD

Multi-agent penetration test tool arrangement and unified calling method and computer equipment

The invention discloses a multi-agent penetration test tool arrangement and unified calling method and computer equipment, and the method comprises the steps: constructing a semi-centralized multi-agent collaborative framework comprising a main control agent, a reconnaissance agent and an attack agent, and abstracting a penetration test process into an interactive task environment; unified calling and result return of various penetration test tools are realized through a model context protocol, and the expandability and safety verifiability among different tools are ensured; modeling a relationship among a target host, ports, services and vulnerabilities in real time by using a dynamic knowledge graph, and performing denoising, association and semantic alignment on multi-source tool output in combination with a preference-driven chained thinking mechanism to form a context-aware knowledge fusion module; and taking the fused knowledge as decision input, guiding multiple agents to complete task planning, tool selection and command generation, and realizing full-process automation from information collection to vulnerability utilization.
Owner:NANJING UNIV OF POSTS & TELECOMM

Penetration testing apparatus

To provide a penetration testing device applicable even to a low-strength improved ground.SOLUTION: A penetration test device 4 for performing a penetration test on a hole wall 21 of a measurement hole 2 in the measurement hole 2 includes a penetration body holding means 44 for holding a penetration body, a slide mechanism 46 for moving the penetration body holding means 44 toward and away from the hole wall 21 of the measurement hole 2, and a measuring means 45 for measuring a penetration resistance force when the penetration body penetrates the hole wall 21.SELECTED DRAWING: Figure 5
Owner:TAISEI CORP

A multi-level quantitative evaluation method for an electronic product information clearing, verifying and tracing credible closed loop system

PendingCN122346411ATechnology developmentAttack
The application discloses a kind of multi-level quantitative evaluation methods for electronic product information clearing, verification and traceable credible closed-loop system, comprising S100, evaluation framework establishment and test environment preparation step: S110, define evaluation model, the evaluation model includes clearing effect layer (L1), verification credible layer (L2), trace and authentication layer (L3), system behavior and security layer (L4) and performance and efficiency layer (L5).The application has the advantages that: from qualitative to quantitative: a large number of quantitative indicators such as KL divergence, bit recovery rate, throughput are introduced, and the evaluation results are objective, accurate and comparable.The method carries out deep security testing: not only test function, but also take the system itself as attack target, carry out penetration testing and process behavior monitoring, can find deeply hidden design defects and security vulnerabilities, which cannot be achieved by traditional function testing.At the same time, the method can guide technology development, and provide decision basis for procurement and supervision;And high automation and repeatability.
Owner:GUIZHOU UNIV

Permeation test effect evaluation method and system based on attack mode framework

The invention relates to the technical field of information security, in particular to a penetration test effect evaluation method and system based on an attack mode framework, and the method comprises the steps: firstly, constructing an evaluation model comprising a target layer, a criterion layer and an index layer; the evaluation indexes under each criterion are weighted through a large language model, and the indexes are quantitatively scored by experts. And for each criterion, on the basis of a grey theory, calculating a comprehensive evaluation vector of the criterion by using index scores, weights, a preset comment set and a whitening weight function so as to obtain a quantitative score and a qualitative evaluation result. And finally, calculating a final comprehensive evaluation result of the target layer by integrating the quantitative score vectors and the criterion weights of all the criteria. During decision making, the final result needs to be combined with the qualitative evaluation conclusion of each criterion so as to formulate a comprehensive and targeted security reinforcement strategy. According to the invention, the accuracy of penetration test effect evaluation is improved.
Owner:AIR FORCE UNIV PLA

Standard penetration test device

To provide a standard penetration test device that can be made smaller.SOLUTION: A standard penetration test device 1 comprises: a drilling mechanism 3 that holds a rod with a drilling tool connected to the bottom so that the rod can rotate and descend and that uses the drilling tool to drill a hole in the ground that is a measurement position where an N value is determined; a first swivel support 4 that rotatably supports the drilling mechanism 3 to allow the drilling mechanism 3 to be retracted from the measurement position; a hydraulic motor 5 that is provided at an upper end of the first swivel support 4 and rotates the rod held by the drilling mechanism 3 via a gear; an impact mechanism 6 that is connected via a rod to a sampler placed in the hole drilled by the drilling mechanism 3 and drives the sampler into the ground to determine the N value; and a second swivel support 7 that rotatably supports the impact mechanism 6 to allow the impact mechanism 6 to be retracted from the measurement position.SELECTED DRAWING: Figure 1B
Owner:TRAVERSE INC

A multi-model cooperative penetration testing method, device and electronic equipment

A multi-model cooperative penetration testing method, device and electronic equipment, relating to the field of data processing. In the method, target asset information and external knowledge data of a target system are obtained, the target system being an object to be penetrated; the target asset information is analyzed in combination with the external knowledge data to obtain corresponding structured penetration data; the current state of the target system is obtained, and the current state and the structured penetration data are input into a preset large language model to generate a penetration testing strategy; based on the penetration testing strategy, a preset reinforcement learning algorithm is used to generate an attack path; the original attack code corresponding to the attack path is input into a preset generative adversarial network to generate obfuscated attack code; and based on the attack path and the obfuscated attack code, the target system is penetrated to obtain a penetration testing result. The technical solution provided by the present application improves the penetration testing coverage.
Owner:BEIJING TIANFANG SECURITY TECH CO LTD

Penetration test method and equipment for vehicle digital key system and medium

The invention provides a penetration test method and device for a vehicle digital key system and a medium, and relates to the technical field of remote data processing.The method comprises the steps that a vehicle state abnormal degree value is obtained through state data of a target vehicle before and after a first test case, and training samples are further stored in a partitioned mode; respectively training a generator and a discriminator based on the training samples stored in the partitions; inputting the random number into a generator which completes at least one round of training to obtain a second test case, and obtaining a decision value corresponding to the second test case according to a discriminator; if the judgment value is smaller than a preset judgment threshold value, sending the judgment value to a target API interface for testing; according to the method, generation of a large number of invalid or redundant test cases is effectively avoided, automatic directional detection and accurate triggering of potential security vulnerabilities such as authentication bypassing, session hijacking and unauthorized control are achieved, and penetration test efficiency and vulnerability discovery capability are remarkably improved.
Owner:SHANDONG ZELU SAFETY TECH CO LTD

System security vulnerability determination method and device, equipment and storage medium

The invention discloses a system security vulnerability determination method and device, equipment and a storage medium. The method comprises the following steps: training an offline reinforcement learning model by using an offline data set of a target system to obtain a target strategy model; respectively inputting the at least two system states into a target strategy model to obtain a target attack action output by the target strategy model; and performing an automatic penetration test on the target system according to the target attack action, and judging whether the target system has security vulnerabilities or not. According to the method, the training process of the off-line reinforcement learning model is applied to the off-line data set, the target attack actions in different system states are output according to the trained target strategy model to carry out permeability testing on the target system, system security vulnerabilities are determined, a high-simulation on-line training environment does not need to be built, and the system security vulnerabilities are determined. The risk problems of service interference, risk control triggering and the like caused by an online training model are solved, decision support is provided for security reinforcement of a target system, and the system security is improved.
Owner:AGRICULTURAL BANK OF CHINA

Contextual weakness scoring during network penetration testing

An autonomous pentesting agent may execute an autonomous pentest of a network including a first network asset and additional network assets that are downstream from the first network asset within attack paths of the autonomous pentest. The autonomous pentesting agent may gain unauthorized access to the first network asset, and, based on accessing the first network asset, gain unauthorized access to the additional network assets. The autonomous pentesting agent may generate, as part of the autonomous pentest, scores for the first network asset and the additional network assets. A first score for the first network asset may be based on a first weakness score of the first network asset and on additional weakness scores corresponding to the additional network assets that are downstream from the first network asset. The autonomous pentesting agent may output, based on the autonomous pentest, a ranking of network assets based on the scores.
Owner:HORIZON 3 AI INC

Security test method and device for industrial real-time database and storage medium

The invention discloses a security test method and device for an industrial real-time database and a storage medium, and relates to the technical field of industrial internet. The method comprises the following steps: based on a three-security partition architecture, realizing security test on the industrial real-time database by verifying the transmission security of each interval. The logic isolation test between the first security zone and the second security zone emphatically checks access control strategies, industrial protocol transmission integrity and abnormal traffic filtering. The physical isolation test between the first security area or the second security area and the third security area comprises the steps of verifying one-way transmission and data integrity of the forward isolation device and verifying formats and security policies by the reverse isolation device. The cross-three-zone linkage transmission test covers end-to-end data transmission security verification, a simulation attack penetration test from a third security zone to a first security zone, and an emergency mechanism test under an isolation device fault. According to the method, the safety of the industrial real-time database can be improved through a three-partition testing method.
Owner:CHINA IND INTERNET RES INST

Adaptive domain penetration testing method, system and equipment and storage medium

The invention relates to the technical field of computers, and provides a self-adaptive domain penetration testing method, system and device and a storage medium, the method comprises the following steps: S1, detecting a target domain environment to obtain environment information of a target domain; s2, defining a deep Q network based on the environment information; s3, a construction agent is trained based on the deep Q network, and a domain penetration test model is constructed; and S4, based on the intelligent agent, according to the change of the target domain environment, adaptively generating a penetration test path which meets the penetration test target and has the maximum accumulated reward. According to environment information of the domain environment, a deep Q network of reinforcement learning is adopted as a core algorithm of an intelligent agent, the domain penetration test model is constructed, penetration test analysis is performed on the dynamically changing domain environment, self-adaptive generation of the penetration test path is realized, the safety condition of the domain environment can be effectively evaluated, and safety and stability of the domain environment are guaranteed.
Owner:NANJING NANZI DIGITAL SECURITY TECH CO LTD

A method and system for mining privilege-related vulnerabilities in power monitoring systems

PendingCN122339727AData packData set
This invention discloses a method and system for mining permission-related vulnerabilities in power monitoring systems. First, it automates login to the target system to obtain valid test sessions. Then, it simulates user operations to trigger system function interfaces, capturing network request data during the interaction process and constructing an interface dataset. Data packets are filtered and analyzed, and sensitive traffic with abnormal permissions is identified based on a large language model. Cookies are replaced and replay tests are performed. The original response and the replay response are compared, and the presence of horizontal privilege escalation vulnerabilities is determined by calculating structural similarity. This invention effectively overcomes the shortcomings of traditional automated tools, such as high false positives and false negatives and poor flexibility due to a lack of dynamic decision-making capabilities, by constructing a complete closed-loop process of automated login, interface data collection, intelligent identification using a large language model, and cookie replacement and replay. This significantly improves the intelligence level of penetration testing and the accuracy of vulnerability mining.
Owner:NARI INFORMATION & COMM TECH

Intelligent in-situ permeation device and use method

The invention discloses an intelligent in-situ permeation device and a use method, and belongs to the technical field of geotechnical engineering test equipment, and the intelligent in-situ permeation device comprises a supporting structure, an outer ring cylinder and an inner ring cylinder which are coaxially arranged, a double-ring lifting structure and a drilling groove structure. The supporting structure is integrally suspended and fixed through the circular track and the supporting legs; the double-ring lifting structure drives the double-ring cylinder to vertically lift; the groove drilling structure moves in the circumferential direction of the circular track through the moving trolley, and the position of the groove drilling assembly is adjusted in the radial direction through the transverse movement driving assembly, so that the groove drilling assembly is accurately positioned below the bottom edge of the double-ring cylinder. According to the device, an elastic telescopic rod self-adaptive extension and dynamic path tracking mechanism is adopted, when a double-ring cylinder is pressed downwards, a groove drilling assembly is tightly attached to the cylinder wall to synchronously drill an annular pit completely matched with the outer diameter of the double rings, and pit drilling-cylinder falling integrated operation is achieved. The problems of size deviation, ring cylinder inclination and sealing failure caused by traditional pre-digging are solved, and the precision and efficiency of the double-ring penetration test are improved.
Owner:KUNMING UNIV OF SCI & TECH

Password guessing method based on multi semantic fusion probability context-free grammar

ActiveCN121479754BMathematical modelsSemantic analysisPassword policyPassword
The present application relates to the technical field of information security, and aims at the problems that password guessing based on probabilistic context-free grammar is difficult to identify multi-semantic patterns and the semantic guidance strength is uncontrollable, and proposes a password guessing method based on multi-semantic fusion of probabilistic context-free grammar: enumerating sub-strings in the training password, identifying semantic segments according to simple, date, vocabulary and name patterns and prioritizing disambiguation, dynamically planning segmentation according to the principle of maximum semantic coverage and least semantic segments, setting semantic enhancement parameters β for each semantic pattern during training to weight and normalize the count, and outputting the candidate password dictionary according to the probability priority queue during generation, which is suitable for efficient password guessing in offline password audit, password policy evaluation and penetration testing.
Owner:NANKAI UNIV