Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

44 results about "Port scan" patented technology

Asset vulnerability detection method and device, electronic equipment and storage medium

The invention discloses an asset vulnerability detection method and device, electronic equipment and a storage medium, and relates to the technical field of network security, and the method comprises the steps: actively sending a multi-protocol detection packet to scan a target network segment, and obtaining a first asset set; passively monitoring network traffic to extract asset feature information, and obtaining a second asset set to generate an asset list; port scanning tasks of all assets are dispatched to a plurality of scanning nodes in a distributed and parallel mode, dynamic port scanning is carried out according to a descending order of a plurality of key elements in combination with a port scanning optimization model based on risk prediction, and a full-amount port risk map is constructed; the static layer is matched with known vulnerabilities; the dynamic layer identifies suspicious behaviors deviating from a normal behavior baseline through an anomaly detection algorithm, and obtains an asset vulnerability detection result in combination with a cross validation method; according to the invention, the detection requirements of asset full coverage and early threat discovery in a complex network environment are met.
Owner:GUANGDONG ORIENTAL THOUGHT TECH

Providing obfuscated results to a network scanner

As an example, an asset receives a request from a scanner performing a reconnaissance of a network that includes the asset. The asset sends a response acknowledging receiving the request, indicating that the asset is alive. The asset receives port scan requests associated with ports of the asset. The asset creates fake fingerprints that include incorrect information about ports of the asset. The asset sends the fake fingerprints to the scanner in response to the port scan requests. The asset determines that a scan engine is requesting access to the asset via a particular port of the asset. The asset grants the scan engine access to the asset via the particular port to enable the scan engine to gather asset data associated with the asset for analysis.
Owner:RAPID7 INC

Cybersecurity Analysis and Protection Using Distributed Systems

Cybersecurity reconnaissance, analysis, and scoring uses distributed, cloud or edge-based pools of computing services to provide sufficient scalability for analysis of IT / OT networks using only publicly available characterizations. An in-memory associative array manages a queue of configuration and vulnerability search tasks through at least one public-facing proxy network which uses configurable search nodes to approach the target network with search tools in a desired manner to control certain aspects of the search in order to obtain the desired results, especially when target network behavior adjusts based on counterparty characteristics. A data packet modifier reveals IP addresses of threat actors behind port scans and subsequently block the threat actors.
Owner:QPX LLC

Method, apparatus, and computer software product for port scan detection

This application relates to port scan detection. A method includes identifying, in network data traffic, a set of source node and destination node (26) pairs, each pair having a given source node, a given destination node, and one or more ports (40) accessed in traffic between the nodes in each pair, and computing, for each pair, a respective baseline indicating a first number of ports accessed on the given destination node by source nodes other than the given source node in the pair during a first time period. For each pair, a respective test score is computed indicating a difference between a second number of ports accessed on the given destination node by the given source node in the pair during a second time period and the baseline, and a preventive action is initiated for the given source node for which the test score for any of the pairs is greater than a threshold.
Owner:PALO ALTO NETWORKS INC

Computer network security situation analysis method and device and electronic equipment

The invention relates to the technical field of network security, in particular to a computer network security situation analysis method and device and electronic equipment, and the method comprises the following steps: S1, collecting small attack behavior data of abnormal small-scale data packet transmission, port scanning behavior and long-time session; s2, carrying out aggregation processing on the data collected in the S1, and generating a cumulative effect graph; s3, constructing a cumulative effect recognition model for outputting risk values of potential security threats in the network; s4, calculating the threat level of each network node; s5, dynamically adjusting a preset safety threshold; and S6, when the threat level exceeds the dynamically adjusted safety threshold, automatically generating a corresponding protection strategy. According to the method, cumulative effect identification of tiny attack behaviors is realized through the dynamic aggregation algorithm and the isolated forest algorithm, and the security threshold is adaptively adjusted and the protection strategy is generated in combination with the reinforcement learning algorithm, so that the accuracy of network security situation awareness and the timeliness of protection are improved.
Owner:SHENZHEN ANRUIZE TECH CO LTD

Malicious port scan detection using port profiles

ActiveUS12542789B2Securing communicationSoftware systemDisjoint-set
Methods, apparatus and computer software products implement embodiments of the present invention that include defining, for a given software category, respective, disjoint sets of communication ports that are used by each of a plurality of software systems in the given software category, including at least first and second disjoint sets. A set of port scans are identified in data traffic transmitted between multiple nodes that communicate over a network, each of the port scans including an access, in the data traffic, of a plurality of the communication ports on a given destination node by a given source node during a predefined time period. Upon detecting a port scan by one of the nodes including accesses of at least one of the communication ports in the first set and at least one of the communication ports in the second set, a preventive action is initiated.
Owner:PALO ALTO NETWORKS INC

An intelligent detection method for network abnormal behavior

This invention proposes an intelligent method for detecting abnormal network behavior, including acquiring target network traffic data, constructing a multi-dimensional feature fusion model based on an attention mechanism, and building an abnormal behavior classification model based on deep learning. By automatically allocating attention to different network traffic features through the attention mechanism, it solves the problems of unreasonable feature weight allocation and insufficient feature fusion in traditional methods, significantly improving the detection capability for low-frequency and covert abnormal behaviors and effectively reducing false positive and false negative rates. The classification model employs a hybrid CNN and LSTM structure, taking into account both the local spatial and temporal features of network traffic, and can accurately identify various types of abnormal network behaviors such as DDoS attacks, port scanning, SQL injection, and malicious code propagation, adapting to diverse attack scenarios with high classification accuracy.
Owner:SHIJIAZHUANG ANJIE FUTURE TECHNOLOGY CO LTD

Malicious behavior bypass interception system based on flow analysis and detection

The invention belongs to the technical field of network security protection, and discloses a malicious behavior bypass interception system based on flow analysis and detection, a rule engine quickly matches known attacks based on a dynamic feature library, such as SQL injection, common port scanning, federated learning model combined multi-node cooperative training, and flow time, behavior and content features are combined to realize the flow analysis and detection of malicious behaviors. Unknown threats such as 0day vulnerability variants and low-frequency hidden attacks are accurately captured; in an enterprise mixed service traffic environment, missed judgment of traditional static detection on unknown attacks can be avoided, false alarms caused by data limitation of a single model can be reduced, energy consumption of operation and maintenance personnel for processing invalid alarms is reduced, core assets are prevented from being damaged by novel attacks, and comprehensiveness and reliability of network protection are remarkably improved; a bypass deployment mode is adopted, traffic is obtained through network TAP equipment or traffic mirror images, a service main forwarding link does not need to be intervened, and network delay and single-point failure risks introduced by traditional series deployment are avoided.
Owner:BEIJING LANGU TECHNOLOGY CO LTD

Port scanning detection

This application relates to port scan detection. A method includes identifying, in network data traffic, a set of source node and destination node (26) pairs, each pair having a given source node, a given destination node, and one or more ports (40) accessed in traffic between the nodes in each pair, and computing, for each pair, a respective baseline indicating a first number of ports accessed on the given destination node by source nodes other than the given source node in the pair during a first time period. For each pair, a respective test score is computed indicating a difference between a second number of ports accessed on the given destination node by the given source node in the pair during a second time period and the baseline, and a preventive action is initiated for the given source node for which the test score for any of the pairs is greater than a threshold.
Owner:PALO ALTO NETWORKS INC

Dynamic DAST scanning method and system and readable storage medium

The invention provides a dynamic DAST scanning method and system and a readable storage medium, and belongs to the field of network security and software engineering automation, and the method comprises the steps: automatically triggering a scanning task when a Developops process runs to a sec security node, and obtaining an interface or URL list; the method comprises the following steps of: processing script rendering, event triggering and redirection by adopting a dynamic crawler acquisition entrance which takes Scrapy as a core and is combined with Pyppeteer, and reducing acquisition failure caused by forbidding through strategies such as a proxy pool, a User-Agent, a Referer and session maintenance; after fingerprint identification and port scanning are carried out on the collected URL, tasks are distributed to xray passive scanning and AWVS active scanning by utilizing Celery scheduling; and after field extraction and format unification are carried out on different engine results, the results are written into MongoDB and duplicate removal is carried out, a customized scanning report is generated and returned to a Developops process to serve as sec node output, and therefore automatic safety scanning and early warning repairing are achieved in the development full life cycle.
Owner:UNICLOUD TECH CO LTD

Network equipment detection method and device, program product, medium and electronic equipment

The invention provides a network equipment detection method and device, a program product, a medium and electronic equipment. The method comprises the following steps: acquiring port state information of to-be-detected network equipment, and determining a port scanning strategy according to the port state information; according to the port scanning strategy, scanning the network equipment, and determining open port information and port service information in the network equipment; and performing port detection on the network equipment according to the open port information and the port service information in the network equipment, and determining whether a risk exists in the network equipment or not. The method comprises the following steps: determining a port scanning strategy exclusive to network equipment according to port state information of the network equipment, scanning the network equipment according to the determined port scanning strategy, determining open port information and port service information in the network equipment, and finally detecting the open port in the network equipment to determine the security of the network equipment. And the detection efficiency of the network equipment is improved.
Owner:HANGZHOU DPTECH TECH

A method and system for port scan detection using server logs

The application discloses a method and system for port scanning detection by using server logs, comprising a feature extraction step and a port scanning detection step; first, access logs on a server cluster are collected, then feature extraction is carried out to construct aggregated records describing access IP behaviors, and finally, whether port scanning occurs is judged by using rules or a clustering method according to the number of positive samples, and meanwhile, the detection result is fed back to an administrator and a positive sample database, so that the accuracy of the method is further improved. The application fully considers the actual needs of operation and maintenance safety audit managers, and has strong implementability and applicability.
Owner:NANJING UNIV

A Port Task Processing Method for a Satellite Telemetry, Tracking and Control System

This invention relates to the field of satellite telemetry and remote control technology, and discloses a port task processing method for a satellite telemetry, tracking, and command (TT&C) system, comprising: Step 1, probing all available network interfaces using a port scanner and establishing a multi-path communication channel including public network, private network, and satellite link; Step 2, collecting packet loss rate, latency, bandwidth, and jitter parameters of each path in the multi-path communication channel in real time, and updating the parameters based on a preset period; Step 3, generating a comprehensive score for each path based on the packet loss rate, latency, bandwidth, and jitter parameters. This invention employs a dynamic scoring and switching technology scheme for multi-path communication channels, achieving the technical effect of automatically selecting the optimal path based on real-time network performance. Compared to existing technologies that rely on fixed paths or manually configured switching thresholds, this solves the problems of high transmission latency, high packet loss rate, and inability to adaptively adjust due to network fluctuations.
Owner:BEIJING CREATUNION INFORMATION TECH CO LTD

Network layer security guarantee method and system for remotely accessing intelligent device with body

The invention discloses a network layer security guarantee method and system for remotely accessing an intelligent device with a body, belongs to the technical field of network security and mobile communication networks, and aims to solve the technical problem of how to prevent security threats of port scanning and brute force cracking and guarantee the security of intelligent applications with the body exposed at a public network end. According to the technical scheme, an SDK plug-in is installed on a user side in advance, the SDK plug-in of the user side is authorized, the authorization content comprises the steps that an application list is accessed, corresponding message identification information is carried when a user accesses a corresponding application on the application list, and a public network server side verifies the message identification information; if yes, allowing the user side to access the corresponding application by the public network server side; and if the verification of the message identification information fails, the public network server rejects the user side to access the corresponding application, and silently discards the application to block the unauthorized access.
Owner:INSPUR COMM TECH CO LTD

Alarm method, server, electronic equipment and storage medium

The embodiment of the invention provides an alarm method and device, equipment and a storage medium, and the method can achieve the alarm according to an Internet communication protocol address range corresponding to a server needing to be scanned, an Internet communication protocol address needing to be eliminated, and a port number and a port range corresponding to a port needing to be scanned. According to the embodiment of the invention, the target port of at least one server is scanned, so that the target scanning result with the abnormal condition is obtained, and the target scanning result can be pushed to the corresponding server. According to the invention, ports of the server can be scanned and alarms can be pushed efficiently, which high-risk ports are opened by a related host can be found timely and effectively, and related alarm pushing notifications are provided for timely checking and closing high-risk ports which do not need to be opened; therefore, a server equipment user is reminded to close the open high-risk port based on the target scanning copy result, and the possibility that viruses infect and damage network equipment through the way is effectively prevented and reduced.
Owner:JINAN INSPUR DATA TECH CO LTD

Port scanning detection

This application relates to port scan detection. A method includes identifying, in network data traffic, a set of source node and destination node (26) pairs, each pair having a given source node, a given destination node, and one or more ports (40) accessed in traffic between the nodes in each pair, and computing, for each pair, a respective baseline indicating a first number of ports accessed on the given destination node by source nodes other than the given source node in the pair during a first time period. For each pair, a respective test score is computed indicating a difference between a second number of ports accessed on the given destination node by the given source node in the pair during a second time period and the baseline, and a preventive action is initiated for the given source node for which the test score for any of the pairs is greater than a threshold.
Owner:PALO ALTO NETWORKS INC

Communication method based on dynamic port

The invention discloses a communication method based on a dynamic port, and the method comprises the steps: enabling a client to determine a current first target port number according to a preset first period, a seed value pre-negotiated by the client and an edge node, and a current first timestamp, employing a Hash message authentication code in combination with an encryption algorithm, and enabling the current first target port number to be transmitted to an edge node; and the client switches to the first target port number to communicate with the edge node. A client negotiates a seed value in advance with an edge node. And according to the seed value and the current first timestamp, determining a current first target port number by adopting a Hash message authentication code in combination with an encryption algorithm. The port numbers determined by the client and the edge node at the current moment are ensured to be the same, so that the client and the edge node can normally communicate. Moreover, the timestamps corresponding to different periods are different, so that the target port numbers determined in different periods are different. The port scanning attack risk is reduced, and the security of network communication is improved.
Owner:CHINA TELECOM CORP LTD TECHNOLOGY INNOVATION CENTER +1

Farmland RS485 bus intelligent converter based on dynamic error-avoiding port scanning

The utility model discloses a farmland RS485 bus intelligent converter based on dynamic error-avoiding port scanning. The farmland RS485 bus intelligent converter comprises a microprocessor, a port scanning module, a multipath RS485 communication interface, a storage unit, a clock module and a power supply module. The microprocessor is used as a core and is connected with multiple paths of RS485 communication interfaces in a star topology mode, so that parallel communication of multiple devices is realized; the port scanning module detects the state of a communication interface in real time through cooperation of a signal detection unit and a signal control unit, dynamically avoids an offline port, optimizes the polling efficiency and improves the communication rate. The storage unit is used for caching high-speed transmission data and avoiding data loss caused by rate mismatching; the clock module adopts a high-precision crystal oscillator, provides precise time sequence control and ensures data synchronization; the power supply module provides stable power for each component. According to the utility model, through the modular design and the dynamic optimization function, the problems of low polling efficiency, data loss and insufficient system expansibility in the prior art are solved, and the performance of multi-node long-distance high-speed communication is improved.
Owner:WUXI ZHONGKE OPTOELECTRONICS TECH CO LTD

Intranet terminal type identification method based on machine learning and port scanning

The invention discloses an intranet terminal type identification method based on machine learning and port scanning, and the method comprises the steps: S1, collecting static features: adding collection equipment manufacturer OUI information except an ip address and an mac address; after the mac address is acquired from the network access layer equipment, equipment manufacturer information is acquired by querying an IEEE official OUI database or a locally maintained OUI mapping table; and S2, service port and response message acquisition optimization: a multi-protocol concurrent detection mechanism is adopted, and detection of protocols such as HTTP, HTTPS, SSH, FTP and the like is simultaneously initiated for common service ports. According to the method, terminal feature data are acquired through network scanning detection, the model is trained in combination with a machine learning algorithm, the network access terminal type is automatically identified, and compared with a traditional mode, the network management efficiency and the data accuracy are remarkably improved, the access strategy is accurately set, and the network security protection capability is effectively enhanced.
Owner:中国农业银行股份有限公司江苏省分行

Port scanning method and device, electronic equipment and storage medium

Embodiments of the present application provide a port scanning method and device, electronic equipment and storage medium. The port scanning method comprises: sending a port scanning task request to a scheduling node; receiving task element information and task actual parameters fed back by the scheduling node, wherein the scheduling node has previously constructed an LFSR based on a plurality of scanning targets in scanning information, a plurality of pseudo-random sequences generated by the LFSR have a one-to-one mapping relationship with the plurality of scanning targets, the task element information is used to restore the LFSR, and the task actual parameters include a current state of the LFSR; determining a scanning target set based on the task element information and the task actual parameters, the scanning target set comprising at least one scanning target. Embodiments of the present application can improve the randomness of the distribution of an Internet port scanning task, reduce the risk of scanning behavior being intercepted, and also improve the calculation and transmission efficiency of scanning targets, having the advantage of high execution efficiency of port scanning.
Owner:QI AN XIN TECHNOLOGY GROUP INC +1

A detection method and system for ROS2 communication security vulnerabilities and application thereof

The application discloses a kind of detection methods for ROS2 communication security vulnerabilities.The method comprises the following steps: according to DDSDiscovery protocol, all required scanning UDP ports are obtained, then UDP port scanning is carried out in target LAN, and the communication domain ID where the ROS2 application program is located is obtained;According to the obtained communication domain ID, the basic information scanning of communication domain is carried out, and the basic information of ROS2 application program communication is obtained;According to the basic information obtained in step two, vulnerability detection is carried out on all scanned topics, services and actions respectively, the security thereof is analyzed, and a detection report is generated;The security detection reports of the above obtained topics and / or services and / or actions are merged to generate a complete ROS2 security report.The application also discloses a detection system for implementing the above detection method, and the application of the above detection method or detection system in ROS2 communication security vulnerability detection.
Owner:EAST CHINA NORMAL UNIV

System and method for determining readiness for managed runtime application program interface (API) applications via artificial intelligence

Systems, computer program products, and methods are described herein for determining readiness for managed runtime application program interface (API) applications via artificial intelligence. The present disclosure is configured to scan a set of API applications and their associated custom port hosted within a managed runtime environment using a custom port probe embedded within the managed runtime environment, where the custom port probe is operably coupled to a load balancer, where user traffic within the managed runtime environment is processed by the set of API applications and the custom port; initialize a set of components within the custom port for operation; verify readiness of the set of API application and the custom port probe using an artificial intelligence system; and transmit a notification to the load balancer indicating readiness of the set of API applications.
Owner:BANK OF AMERICA CORP

An automated programming system and method for serial presence detect information

The present application provides an automated programming system and method for serial presence detect information. The system includes: a port scanning module for automatically detecting available serial communication ports on a host and determining the serial communication port to be programmed from the available serial communication ports; an address identification module for automatically identifying and connecting to the EEPROM address of the serial communication port to be programmed; a data reading module for reading original serial presence detect data from an EEPROM chip according to the EEPROM address; a data modification module for obtaining the two-dimensional code information on a memory module, parsing and extracting serial presence detect parameters, and updating the original serial presence detect data in the EEPROM chip according to the serial presence detect parameters; and a data writing module for writing the updated serial presence detect data into the EEPROM chip. Thereby simplifying the programming operation process and improving the programming efficiency and accuracy.
Owner:ZHEJIANG LIJI ELECTRONICS CO LTD

Remote management system of household monitoring equipment

The invention discloses a remote management system of household monitoring equipment, and relates to the technical field of monitoring equipment management, a score generation module obtains an attack score of the monitoring equipment through addition of a nonlocal access frequency normalized value and an unauthorized port scanning frequency normalized value; the attack judgment module judges whether the monitoring equipment is attacked by an attacker or not according to the attack score, and when it is judged that the monitoring equipment is attacked by the attacker, the induction module shuts down the monitoring equipment, induces the attacker to the honeypot equipment, monitors the attack behavior of the attacker on the honeypot equipment and sends the attack behavior to the honeypot equipment. And when the security protection software arranged on the honeypot equipment is attacked by an attacker, the management module selects to shut down all the monitoring equipment or perform other management according to the system vulnerability condition of the monitoring system. When the management system judges that the attacker behavior exists, the monitoring device with the attack risk is closed firstly, then the attacker is induced to attack through the virtual monitoring device, and the use stability and safety of the monitoring device are guaranteed.
Owner:SHENZHEN XINYI INFORMATION TECH CO LTD

Method to detect vulnerable internet services via changes to global port-scanning traffic

A computer-implemented method includes receiving signals via a network at ports on the network, the signals corresponding to scanning activity at the ports by a plurality of sources on the network; the sources are located at a plurality of geographical bins. The method also includes determining a popularity score for each of the ports, based on a number of geographical bins sending signals to the in a first time period; calculating, for each of the geographical bins, a probability of scanning activity occurring at a port in a second time period, resulting in a plurality of probabilities for that port; and calculating, for each of the ports, a surprisingness index based on the plurality of probabilities. The method further includes estimating, in accordance with the popularity score and the surprisingness index for each of the ports, a likelihood that the port is experiencing suspicious scanning activity.
Owner:ORACLE INT CORP

Transmission data security system and method adaptive to switch, and medium

The invention discloses a transmission data security system and method adaptive to a switch, and a medium. A chaotic sequence generation module generates a pseudo-random sequence based on coupled Logistic mapping and Henon mapping; the dynamic port mapping module changes the mapping relation between the physical port and the logic channel in real time according to the chaotic sequence; the chaos driving encryption module maps a chaos sequence into encryption parameters, and dynamically switches among three algorithms of AES-256, SM4 and ChaCha20 and three modes of CBC, CTR and GCM; the port hopping synchronization protocol module establishes a master-slave chaotic synchronization mechanism; the threat detection module detects abnormal behaviors such as port scanning and replay attacks; and the adaptive parameter adjustment module dynamically adjusts the jump period according to the threat level. According to the invention, the data transmission security and the anti-attack capability of the switch are effectively improved.
Owner:SICHUAN ZHIYUAN LIXING TECHNOLOGY CO LTD

An asset feature correlation type intelligent weak password detection and early warning method and system

The application discloses a kind of weak password detection and early warning method and system based on asset feature correlation formula intelligence, method includes: input asset information;Generation asset feature correlation dictionary;Configuration detection task;Select automatic or manual weak password detection task;Scan or identify port;Password collision;Automatic weak password detection report and risk early warning and notification generation;Its efficient asset information management, intelligent password dictionary generation, flexible detection task configuration, diversified detection mode, accurate port scanning identification, automatic report generation and real-time risk early warning and notification etc. together constitute an efficient, accurate and practical weak password detection and early warning system;The application aims at improving network security protection level, ensures asset security.
Owner:XIAN AMAI XINKE TECH CO LTD

Power acquisition system non-inductive migration method based on dynamic port mapping

The invention provides an electric power acquisition system non-inductive migration method based on dynamic port mapping, and belongs to the technical field of electric power acquisition. Twelve asset numbers of an electric energy meter are actively obtained through a transparent transmission module and encrypted and stored, and a concentrator automatically allocates monitoring ports according to the last four asset numbers and establishes a port mapping table; a TCP transparent transmission server is started to realize bidirectional conversion between a carrier frame and a TCP message, an optimal relay path is determined by adopting a carrier relay routing optimization algorithm based on a graph theory minimum spanning tree, time division multiple access time slots are allocated, and a sparse port scanning acceleration algorithm based on compressed sensing is executed to quickly detect a port occupation state. The technical problem that the service interruption time is long due to the fact that the master station needs to reconfigure connection parameters table by table after the communication module of the power acquisition system is replaced is solved.
Owner:QINGDAO EASTSOFT COMM TECH

Autonomous controllable embedded operating system flow monitoring method for power business

The invention relates to an autonomous controllable embedded operating system flow monitoring method for power business. The method comprises the following steps: S1, capturing communication flow data of an industrial protocol in real time; s2, according to the communication flow data, the cloud end detects distributed denial of service attacks, port scanning, illegal instruction injection and data leakage attacks for the power control system in real time by analyzing a space-time interaction mode between devices based on an ST-GAT model; and S3, integrating a lightweight LAKE protocol on intelligent electronic equipment running an autonomous controllable operating system to realize encrypted data transmission, and establishing an end-to-cloud secure communication link in a resource-constrained environment. According to the method, real-time efficient acquisition and end-to-end encryption of the network traffic of the power terminal are realized, and various potential risks and attack behaviors can be intelligently identified through global modeling of network communication behaviors.
Owner:STATE GRID INFORMATION & TELECOMM GRP CO LTD +4

Transmission data security system, method and medium adapted to a switch

The application discloses a transmission data security system, method and medium suitable for a switch, a chaotic sequence generation module generates a pseudo-random sequence based on coupled Logistic mapping and Henon mapping; a dynamic port mapping module changes the mapping relationship between a physical port and a logical channel in real time according to the chaotic sequence; a chaotic driving encryption module maps the chaotic sequence into encryption parameters, and dynamically switches among three algorithms of AES-256, SM4 and ChaCha20 and three modes of CBC, CTR and GCM; a port hopping synchronization protocol module establishes a master-slave chaotic synchronization mechanism; a threat detection module detects abnormal behaviors such as port scanning and replay attacks; and an adaptive parameter adjustment module dynamically adjusts a hopping period according to a threat level. The application effectively improves the security and attack resistance of switch data transmission.
Owner:SICHUAN ZHIYUAN LIXING TECHNOLOGY CO LTD