Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

16 results about "Port scan" patented technology

An intelligent detection method for network abnormal behavior

This invention proposes an intelligent method for detecting abnormal network behavior, including acquiring target network traffic data, constructing a multi-dimensional feature fusion model based on an attention mechanism, and building an abnormal behavior classification model based on deep learning. By automatically allocating attention to different network traffic features through the attention mechanism, it solves the problems of unreasonable feature weight allocation and insufficient feature fusion in traditional methods, significantly improving the detection capability for low-frequency and covert abnormal behaviors and effectively reducing false positive and false negative rates. The classification model employs a hybrid CNN and LSTM structure, taking into account both the local spatial and temporal features of network traffic, and can accurately identify various types of abnormal network behaviors such as DDoS attacks, port scanning, SQL injection, and malicious code propagation, adapting to diverse attack scenarios with high classification accuracy.
Owner:SHIJIAZHUANG ANJIE FUTURE TECHNOLOGY CO LTD

Dynamic DAST scanning method and system and readable storage medium

The invention provides a dynamic DAST scanning method and system and a readable storage medium, and belongs to the field of network security and software engineering automation, and the method comprises the steps: automatically triggering a scanning task when a Developops process runs to a sec security node, and obtaining an interface or URL list; the method comprises the following steps of: processing script rendering, event triggering and redirection by adopting a dynamic crawler acquisition entrance which takes Scrapy as a core and is combined with Pyppeteer, and reducing acquisition failure caused by forbidding through strategies such as a proxy pool, a User-Agent, a Referer and session maintenance; after fingerprint identification and port scanning are carried out on the collected URL, tasks are distributed to xray passive scanning and AWVS active scanning by utilizing Celery scheduling; and after field extraction and format unification are carried out on different engine results, the results are written into MongoDB and duplicate removal is carried out, a customized scanning report is generated and returned to a Developops process to serve as sec node output, and therefore automatic safety scanning and early warning repairing are achieved in the development full life cycle.
Owner:UNICLOUD TECH CO LTD

Network layer security guarantee method and system for remotely accessing intelligent device with body

The invention discloses a network layer security guarantee method and system for remotely accessing an intelligent device with a body, belongs to the technical field of network security and mobile communication networks, and aims to solve the technical problem of how to prevent security threats of port scanning and brute force cracking and guarantee the security of intelligent applications with the body exposed at a public network end. According to the technical scheme, an SDK plug-in is installed on a user side in advance, the SDK plug-in of the user side is authorized, the authorization content comprises the steps that an application list is accessed, corresponding message identification information is carried when a user accesses a corresponding application on the application list, and a public network server side verifies the message identification information; if yes, allowing the user side to access the corresponding application by the public network server side; and if the verification of the message identification information fails, the public network server rejects the user side to access the corresponding application, and silently discards the application to block the unauthorized access.
Owner:INSPUR COMM TECH CO LTD

Port scanning method and device, electronic equipment and storage medium

Embodiments of the present application provide a port scanning method and device, electronic equipment and storage medium. The port scanning method comprises: sending a port scanning task request to a scheduling node; receiving task element information and task actual parameters fed back by the scheduling node, wherein the scheduling node has previously constructed an LFSR based on a plurality of scanning targets in scanning information, a plurality of pseudo-random sequences generated by the LFSR have a one-to-one mapping relationship with the plurality of scanning targets, the task element information is used to restore the LFSR, and the task actual parameters include a current state of the LFSR; determining a scanning target set based on the task element information and the task actual parameters, the scanning target set comprising at least one scanning target. Embodiments of the present application can improve the randomness of the distribution of an Internet port scanning task, reduce the risk of scanning behavior being intercepted, and also improve the calculation and transmission efficiency of scanning targets, having the advantage of high execution efficiency of port scanning.
Owner:QI AN XIN TECHNOLOGY GROUP INC +1

System and method for determining readiness for managed runtime application program interface (API) applications via artificial intelligence

Systems, computer program products, and methods are described herein for determining readiness for managed runtime application program interface (API) applications via artificial intelligence. The present disclosure is configured to scan a set of API applications and their associated custom port hosted within a managed runtime environment using a custom port probe embedded within the managed runtime environment, where the custom port probe is operably coupled to a load balancer, where user traffic within the managed runtime environment is processed by the set of API applications and the custom port; initialize a set of components within the custom port for operation; verify readiness of the set of API application and the custom port probe using an artificial intelligence system; and transmit a notification to the load balancer indicating readiness of the set of API applications.
Owner:BANK OF AMERICA CORP

An asset feature correlation type intelligent weak password detection and early warning method and system

The application discloses a kind of weak password detection and early warning method and system based on asset feature correlation formula intelligence, method includes: input asset information;Generation asset feature correlation dictionary;Configuration detection task;Select automatic or manual weak password detection task;Scan or identify port;Password collision;Automatic weak password detection report and risk early warning and notification generation;Its efficient asset information management, intelligent password dictionary generation, flexible detection task configuration, diversified detection mode, accurate port scanning identification, automatic report generation and real-time risk early warning and notification etc. together constitute an efficient, accurate and practical weak password detection and early warning system;The application aims at improving network security protection level, ensures asset security.
Owner:XIAN AMAI XINKE TECH CO LTD

Power acquisition system non-inductive migration method based on dynamic port mapping

The invention provides an electric power acquisition system non-inductive migration method based on dynamic port mapping, and belongs to the technical field of electric power acquisition. Twelve asset numbers of an electric energy meter are actively obtained through a transparent transmission module and encrypted and stored, and a concentrator automatically allocates monitoring ports according to the last four asset numbers and establishes a port mapping table; a TCP transparent transmission server is started to realize bidirectional conversion between a carrier frame and a TCP message, an optimal relay path is determined by adopting a carrier relay routing optimization algorithm based on a graph theory minimum spanning tree, time division multiple access time slots are allocated, and a sparse port scanning acceleration algorithm based on compressed sensing is executed to quickly detect a port occupation state. The technical problem that the service interruption time is long due to the fact that the master station needs to reconfigure connection parameters table by table after the communication module of the power acquisition system is replaced is solved.
Owner:QINGDAO EASTSOFT COMM TECH

Autonomous controllable embedded operating system flow monitoring method for power business

The invention relates to an autonomous controllable embedded operating system flow monitoring method for power business. The method comprises the following steps: S1, capturing communication flow data of an industrial protocol in real time; s2, according to the communication flow data, the cloud end detects distributed denial of service attacks, port scanning, illegal instruction injection and data leakage attacks for the power control system in real time by analyzing a space-time interaction mode between devices based on an ST-GAT model; and S3, integrating a lightweight LAKE protocol on intelligent electronic equipment running an autonomous controllable operating system to realize encrypted data transmission, and establishing an end-to-cloud secure communication link in a resource-constrained environment. According to the method, real-time efficient acquisition and end-to-end encryption of the network traffic of the power terminal are realized, and various potential risks and attack behaviors can be intelligently identified through global modeling of network communication behaviors.
Owner:STATE GRID INFORMATION & TELECOMM GRP CO LTD +4

Transmission data security system, method and medium adapted to a switch

The application discloses a transmission data security system, method and medium suitable for a switch, a chaotic sequence generation module generates a pseudo-random sequence based on coupled Logistic mapping and Henon mapping; a dynamic port mapping module changes the mapping relationship between a physical port and a logical channel in real time according to the chaotic sequence; a chaotic driving encryption module maps the chaotic sequence into encryption parameters, and dynamically switches among three algorithms of AES-256, SM4 and ChaCha20 and three modes of CBC, CTR and GCM; a port hopping synchronization protocol module establishes a master-slave chaotic synchronization mechanism; a threat detection module detects abnormal behaviors such as port scanning and replay attacks; and an adaptive parameter adjustment module dynamically adjusts a hopping period according to a threat level. The application effectively improves the security and attack resistance of switch data transmission.
Owner:SICHUAN ZHIYUAN LIXING TECHNOLOGY CO LTD

Method and device for port scanning detection and computer software product

The invention relates to a method and device for port scanning detection and a computer software product. A method includes identifying a set of pairs of source and destination nodes (26) in network data traffic, each pair having a given source node, a given destination node, and one or more ports (40) accessed in traffic between nodes in each pair, and calculating a respective baseline for each pair, the baseline indicates a first number of ports accessed by source nodes other than a given source node in the pair on a given destination node during a first period of time. For each pair, a respective test score is calculated that indicates a difference between a second number of ports accessed by a given source node of the pair on a given destination node during a second period and the baseline, and a preventive action is initiated for a given source node of any of the pairs for which the test score is greater than a threshold.
Owner:PALO ALTO NETWORKS INC

A port scanning detection method, system, electronic device and storage medium

The application discloses a port scanning detection method and system, an electronic device and a storage medium. The method comprises the following steps: loading an eBPF program and creating a first eBPF Map for storing a whitelist; hooking a first eBPF program related to a first kernel function of port listening, dynamically constructing the whitelist during port listening; hooking a second eBPF program related to a second kernel function of network connection establishment, extracting a destination port number and querying the whitelist when receiving a network connection request; if the query is not hit, determining an abnormal scanning event, and collecting connection information and reporting to the user state. The application can detect port scanning behavior in real time and accurately in the kernel state with low performance overhead, and the detection mechanism is difficult to bypass, solving the problems of poor real-time performance, high performance overhead and easy bypassing in the prior art.
Owner:BEIJING BAIGEFEICHI TECH LLC

System and method for determining readiness for managed runtime application program interface (API) applications via artificial intelligence

Systems, computer program products, and methods are described herein for determining readiness for managed runtime application program interface (API) applications via artificial intelligence. The present disclosure is configured to scan a set of API applications and their associated custom port hosted within a managed runtime environment using a custom port probe embedded within the managed runtime environment, where the custom port probe is operably coupled to a load balancer, where user traffic within the managed runtime environment is processed by the set of API applications and the custom port; initialize a set of components within the custom port for operation; verify readiness of the set of API application and the custom port probe using an artificial intelligence system; and transmit a notification to the load balancer indicating readiness of the set of API applications.
Owner:BANK OF AMERICA CORP

Hot-pluggable HTTP (Hyper Text Transport Protocol) service framework system and method free from port monitoring

PendingCN121833576ATransmissionElectric digital data processingHot swappingHyper text transport protocol
The invention discloses a port-monitoring-free hot-pluggable HTTP (Hyper Text Transport Protocol) service framework system and a port-monitoring-free hot-pluggable HTTP service framework method, which are applied to a service node, and the system comprises a node starting module which is used for initiating an encrypted outbound tunnel to a control plane after the service node is started, so that any new port does not need to be opened; a light HTTP parser is arranged in the parsing module, and the parsing module is used for unpacking the received task frame, mapping the unpacked task frame to a service code to execute service logic and returning a response through the outbound tunnel; the task frame monitors an external entrance in a unified manner through the control plane, and after a request is received, the request is packaged into the task frame, and the task frame is safely issued through an outbound tunnel; the hot plug management module is used for instantly reporting online / offline of a service node through the outbound tunnel, so that the control plane completes rolling upgrading under the condition that a network strategy is not changed; the method has the beneficial effects that any inbound port does not need to be opened, and the vulnerability utilization risk caused by passive port scanning is eliminated.
Owner:SHENZHEN LEAGSOFT TECH

Asset portrait construction method and device based on multi-protocol full-port scanning

The embodiment of the invention provides an asset portrait construction method and device based on multi-protocol full-port scanning, and the method comprises the steps: carrying out the full-port and full-protocol scanning of all IP addresses through a plurality of independent scanning nodes disposed in a network, and obtaining asset information, including an operation system, a service version and a vulnerability state; transmitting a scanning result through an encryption channel; the structured asset information is stored in a relational database, semi-structured or unstructured data is stored in an NoSQL database, and original scanning logs and snapshots are stored in an object storage system; cleaning, standardizing and tagging the asset data, and constructing a fine-grained asset ledger; dynamically updating the asset data, setting a data verification rule, and performing data quality management and verification by using a data quality tool; a unified data access interface is provided, and access and application of various data scenes are supported. Through a systematic technical architecture, the problems of fragmentation and low efficiency in traditional asset management are solved.
Owner:HUANENG INFORMATION TECH CO LTD

A multi-technology fusion network security health assessment method and system

ActiveCN120151026BSecuring communicationData packOpen port
A multi-technology fusion network security health assessment method and system, in the method, an activity index of an IP address is generated; an open port information is obtained by performing port detection on the IP address with an activity index greater than a first threshold through a configurable port scanning mode; a service detection data packet is sent to the open port; a service type and a version number are extracted according to response information of the service detection data packet to obtain a service change frequency; an asset dynamic score is calculated based on the activity index of the IP address and the service change frequency; the IP address is divided into stable assets and temporary assets according to the asset dynamic score; a low-frequency deep detection mode is used for the stable assets and a high-frequency rapid detection mode is used for the temporary assets to obtain a detection result; the detection result and the asset dynamic score are input into a risk assessment function to calculate a risk security value of each IP address; and an evaluation report is generated according to the security risk value. The application is used for improving the accuracy of enterprise network security evaluation.
Owner:BEIJING FULE TECH CO LTD

Industrial control network vulnerability mining method

PendingCN121814371ATimely investigationimprove securitySecuring communicationPort scanReliability engineering
The invention discloses an industrial control network vulnerability mining method, and an industrial control network vulnerability mining platform comprises the steps that a port scanning module scans ports of all tested devices in an industrial control network under the control of a main control module; the test case generating and loading module is used for generating a test case and loading the test case to the main control module; the Fuzzing engine selects a corresponding test case according to the port scanned by the port scanning module, and sends a test message to the industrial control network according to the test case; and the Monitor module monitors and records a test result of the industrial control network in response to the test message. According to the technical scheme, the problems that industrial control network vulnerabilities are difficult to check in time and potential safety hazards and risks exist in the prior art can be solved.
Owner:CHINA ELECTRONICS CORP 6TH RES INST