Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

29 results about "Program security" patented technology

A security program is a documented set of your company's information security policies, procedures, guidelines, and standards. Your security program should provide a roadmap for effective security management practices and controls.

Trusted authentication system and method based on quantum encryption terminal virtualization

The invention discloses a trusted authentication system and method based on quantum encryption terminal virtualization. Comprising a hardware trusted root module, a virtual trusted root management module, a container environment module, a container mirror image management module, a container monitoring module and a trust chain management module, a safe and credible container operation environment is constructed, a credible authentication mechanism based on quantum random numbers is established, starting and operation of an operation system, a Docker container and an application program are verified step by step, the safe and credible state of system operation is guaranteed, multi-container use is supported, and safe and credible container-level programs are achieved. Therefore, the security problem of multi-program operation of the power dispatching terminal gateway is solved.
Owner:NARI INFORMATION & COMM TECH +4

Implementation method and device of programmable API security gateway

ActiveCN115913750BSoftware engineeringProgram security
This invention discloses a method and apparatus for implementing a programmable API security gateway. The method includes: identifying API interface characteristics and automatically programming policy templates for the API interfaces based on these characteristics; detecting security events of the API interfaces and automatically programming security policy templates for the API interfaces based on these security events; and monitoring the operational status of the API interfaces and automatically adjusting the flow control and security policies associated with the API interfaces. This method and apparatus improve the maintenance efficiency of API interfaces and reduce operational costs.
Owner:CHINA UNITECHS

Binary program vulnerability mining method, device and system based on symbolic execution and taint analysis and medium

The invention provides a binary program vulnerability mining method, device and system based on symbolic execution and taint analysis and a medium, and the method comprises the steps: disassembling a target program, extracting a control flow graph (CFG) and a data flow graph (DFG), recording a node state through a hash table, and generating a feature representation through nonlinear transformation; performing simulation execution based on CFG, DFG and feature representation, recording variable symbol values to obtain path conditions, and recursively solving constraints to generate path mapping; marking input as taint data, recursively calculating a propagation path to generate a taint flow diagram, and determining a taint state after sensitive operation; checking whether the stains are subjected to sensitive operation or not, and if the influence of integral formula calculation exceeds a threshold value, judging that potential vulnerabilities generate a candidate set; and calculating grades through a risk assessment formula, and generating a report containing positions, types, grades and repair suggestions. The method combines symbolic execution and taint analysis, can comprehensively and accurately detect vulnerabilities, has remarkable precision and efficiency advantages, and is suitable for complex program security analysis.
Owner:HUBEI CENT CHINA TECH DEV OF ELECTRIC POWER

An application software development test system with real-time vulnerability detection

The application belongs to the technical field of application software development test, and discloses an application software development test system with real-time vulnerability detection, which comprises a code real-time collection module, a multi-dimensional vulnerability detection module, a vulnerability accurate positioning module, a vulnerability risk quantitative evaluation module, a dynamic repair guidance module, a data storage module, a visual interaction module and an iterative optimization module, and each module cooperates to form a whole-process closed-loop vulnerability detection and management and control system. The application software development test system with real-time vulnerability detection is adopted, real-time capture, accurate positioning, risk evaluation and dynamic repair suggestion output of the vulnerability are realized, and the software development test efficiency and application program security are improved.
Owner:BEIJING JIAXINYUAN TECHNOLOGY CO LTD

A processor chip branch prediction target buffer security enhancement method and electronic device

The application provides a processor chip branch prediction buffer security strong method and an electronic device. The method comprises: a security domain private key generation and application method, dividing a program security domain and generating two private security keys for each security domain, and ensuring that randomization seeds adopted by different security domains are irrelevant; a structure design of a branch prediction buffer with a label domain and a data domain separated, which is combined with a branch prediction buffer skew lookup and update mechanism to realize a security branch prediction buffer skew randomization lookup and update mechanism within a system life cycle, and the structure design of the branch prediction buffer with the label domain and the data domain separated is combined to realize security within the system life cycle.
Owner:SOUTHEAST UNIV

Code execution method and device, and storage medium

The application discloses a code execution method and device and a storage medium. The application relates to the technical field of program security, and the method comprises the following steps: performing abstract syntax tree conversion on to-be-executed code to obtain a tree-shaped code structure; checking each tree node in the tree-shaped code structure to obtain checking information, adjusting the tree-shaped code structure according to the checking information, and obtaining an adjusted tree-shaped code structure; generating target execution code according to the adjusted tree-shaped code structure; and executing the target execution code in a restricted environment, wherein the restricted environment refers to a code execution environment after a detection function is modified according to a preset restricted object list. Through the application, the problem that the code security checking method in the prior art is not accurate enough and the security of execution code in a system is low, thereby leading to poor system stability, is solved.
Owner:INDUSTRIAL AND COMMERCIAL BANK OF CHINA

Application security risk detection method, device, equipment, medium and product

The application relates to the technical field of artificial intelligence, and provides an application program security risk detection method, device, equipment, medium and product, the application program security risk detection method comprises the following steps: obtaining an application program to be identified; inputting the application program to be identified into a preset identification model to obtain a detection result output by the preset identification model; the preset identification model is obtained by training data of an original application program installation package; the preset identification model comprises multiple intelligent agents working respectively, and the intelligent agents are used for executing different function tasks, wherein the function tasks comprise task scheduling, data analysis and result decision. Through the above mode, the intelligent level and performance index of the identification model can be significantly improved, so that the accuracy of the security risk detection result of the application program is improved.
Owner:CHINA MOBILE GROUP ZHEJIANG +3

Application program security control method and device, equipment, medium and product

The invention discloses an application program safety control method and device, equipment, a medium and a product. The method comprises the steps of obtaining a screenshot image and corresponding user interface structure information when a user operates a current application program; based on the screenshot image and the user interface structure information, using a preset first large language model to perform user behavior analysis to determine whether the user has a high-risk behavior; and if the user has the high-risk behavior, triggering safety early warning. According to the invention, the high-risk behavior of the user can be accurately identified and early warned, and the risk identification precision and adaptability are effectively improved.
Owner:CHINA MOBILE INTERNET CO LTD +1

Program running method and device, equipment, medium and program product

The invention discloses a program running method and device, equipment, a medium and a program product, and relates to the technical field of computers. The method comprises the following steps: acquiring a mirror image file corresponding to a first application program; performing data analysis on the mirror image file to obtain attribute data used for indicating the program container in the running process in the mirror image file; generating second attribute data corresponding to the first attribute data based on the attribute data; and configuring the second attribute data into the mirror image file, and running the program container based on the second attribute data to obtain a container running result. Namely, a mode of replacing the original attribute data with the autonomously constructed security data avoids constructing an independent isolation environment to run the program container, so that the overhead of computing resources is reduced while the safe operation of the program container is ensured, and the verification efficiency of the program security is improved.
Owner:TENCENT TECHNOLOGY (SHENZHEN) CO LTD

Windows platform-based application security authentication method and device

The application belongs to the technical field of information security, and provides a kind of application program security authentication method and device based on Windows platform, the method includes: obtaining the portable executable PE file corresponding to the application program of Windows platform;PE file is encrypted, and the encrypted PE file is written into the target resource segment of preset PE file, to obtain target PE file;Run target PE file, and under the condition that target PE file passes target authentication authentication, obtain encrypted PE file and decrypt, to obtain decrypted file;Wherein, target authentication authentication includes user identity authentication and user authority authentication, or user identity authentication.The method can realize the identity authentication mechanism based on password technology to the application program of Windows platform under the premise of zero modification, meet the relevant requirements of secret evaluation, improve the security of original PE file identity authentication and reduce the authentication cost.
Owner:CHINA ELECTRONICS STANDARDIZATION INST

A Method and Device for Improving the Security of Cloud-Hosted Web Applications Based on Containers

The present invention discloses a method and device for improving the security of cloud-hosted Web application programs based on containers. The method includes: constructing a Web application and building a MongoDB database cluster using Docker container instances in the Web application; wherein the Web application includes multiple database containers; classifying the data stored in the multiple database containers based on the types of the multiple database containers to obtain a data classification result; constructing a jump defense model according to the data classification result and the characteristics of the MongoDB database cluster, and outputting the distribution characteristics of the data stored in the multiple database containers in the Docker container instances; configuring a load balancer for the MongoDB database cluster based on the distribution characteristics to perform data distribution and mapping processing to the host, so that the jump defense model provides a single interface to each database container. The present invention can implement the use of virtual technology with very little memory, and reduce the damage degree of web application programs through container jumps.
Owner:HUANENG CLEAN ENERGY RES INST +1

Operating system kernel authentication system based on RUST language

The invention discloses an operating system kernel authentication system based on an RUST language, and relates to the technical field of software authentication, the operating system kernel authentication system comprises a quality evaluation module and a security evaluation module, the quality evaluation module adopts different evaluation modes according to whether a target kernel source code is open or not; for an open source operating system, static code analysis is carried out on a kernel of the open source operating system by using a coding specification based on an RUST language, and then evaluation is carried out through a quality evaluation scheme; the method comprises the following steps: aiming at an operating system kernel of which internal codes are not disclosed, evaluating the system kernel based on a sequence of specified evaluation, plan evaluation and execution evaluation defined in an ISO / IEC 25040 standard; and the security evaluation module evaluates the function security and the information security of the operating system kernel. According to the method, the security features contained in the Rust language design are fully utilized, redundancy judgment on the program security features guaranteed by the Rust compiler is reduced, and therefore the workload of the authentication process is reduced.
Owner:EAST CHINA INST OF COMPUTING TECH +1

Method for obfuscating and hiding codes to improve program security

The invention provides a method for obfuscating and hiding codes to improve program security, which comprises the following steps: S1, obfuscating the codes of software to change the structure and form of the codes, the codes of the software comprising core codes and non-core codes; the obfuscated code comprises letter name obfuscation: replacing one or any combination of a variable name, a function name and a file name of a source code with a letter for distinguishing capital and small letters; s2, structures of core codes in the codes obtained in the step S1 are reorganized through hidden codes, all the core codes are stored in a hidden file, and original codes are deleted; and S3, packaging the obfuscated and hidden codes into a plurality of files, wherein each packaged file has a hidden file storing the hidden codes. According to the method and the device, a developer can configure the rapid reinforcing software through the simple annotation mark, the core code of the software is reinforced and protected, and the security of the software can be greatly improved.
Owner:JIANGSU CHUANZHI PODCAST EDUCATIONAL TECH CO LTD

Vulnerability feature recognition method and device based on abnormal object, equipment and medium

The invention discloses a vulnerability feature recognition method and device based on an abnormal object, equipment and a medium, and relates to the field of interactive application program security testing, and the method comprises the steps: creating a throwable abnormal object at a vulnerability trigger point; judging version information of the current Java development tool, calling a Java language access interface to generate a first identification code if the version of the Java development tool is 1.8 or below, and generating a second identification code by acquiring a field in a stack backtracking field of the abnormal object capable of being thrown if the version of the Java development tool is 1.8 or above; and if the version of the Java development tool is 1.8 or below, forming a vulnerability feature code by the first identification code and the context information. According to the main technical scheme and the effects, the operation performance is remarkably improved, the system resource overhead is reduced, the performance interference of the IAST Agent on a main service system in a high-concurrency environment in the version JDK1.9 and above is greatly reduced, and the feasibility of production environment deployment is enhanced.
Owner:HANGZHOU MORESEC TECH CO LTD

Data identity recognition for semiconductor devices

Systems, apparatuses, and methods related to data identity recognition for semiconductor devices are described. A system includes a host and a memory device coupled to the host via an interconnect bus. The host includes a host security manager configured to encrypt data of a command, perform a memory integrity check, allow access to memory of a memory device corresponding to an address of a command based on which entity associated with the host sent the command, generate security keys, program security keys into the memory device, program encryption ranges, or any combination thereof. The memory device includes a memory encryption manager and a memory device security manager. The memory device security manager is configured to detect whether a command was sent from a trusted domain of the host or non-trusted domain of the host and identify which entity associated with the host initiated the command.
Owner:MICRON TECHNOLOGY INC

A software deployment method, device, computer device, and storage medium

An embodiment of the present application discloses a software deployment method, device, computer device, storage medium, and computer program product. An embodiment of the present application can obtain encrypted code data of a software and a software launcher, where the software launcher is used to assist in starting the software; determine program security information during the operation of the software; modify code parameter information corresponding to the program security information in the software launcher based on the program security information; generate software deployment data of the software according to the encrypted code data and the modified software launcher; and deploy the software on a target device according to the software deployment data. This solution can be applied to various scenarios such as cloud technology, artificial intelligence, intelligent transportation, and assisted driving, and this solution can improve the security and efficiency of software deployment.
Owner:TENCENT TECHNOLOGY (SHENZHEN) CO LTD

Program encryption method and device, storage medium and program product

The invention provides a program encryption method and device, a storage medium and a program product, relates to the technical field of computers, and can improve the problem of program leakage and ensure the security of a program. Acquiring a public key in the key pair and a source code of the application program, and compiling the source code by using network assembly to obtain an original byte code; the key pair is the same as a key pair in a second device, and the second device is a device for deploying the application program; generating a symmetric key based on the public key, encrypting the original byte code by using the symmetric key to obtain an encrypted byte code, and encrypting the symmetric key by using the public key to obtain an encrypted symmetric key; and rewriting the code section in the original byte code to generate a rewritten byte code of which the function section is the same as that of the original byte code. Function code logic in a code section of the rewritten byte code meets a function statement in a function section; and writing the encrypted byte code, the decryption logic of the encrypted byte code and the encrypted symmetric key into the self-defined section of the rewritten byte code to obtain an encrypted program package.
Owner:CHINA CONSTRUCTION BANK +1

Software security assessment method, system and readable storage medium

ActiveCN115906094BPlatform integrity maintainanceThird partyProgram security
The present invention discloses a software security assessment method, system, and readable storage medium. The method includes the following steps: extracting fingerprint features of third-party libraries in software delivery files; obtaining vulnerability information disclosed by the third-party libraries and extracting vulnerability features; calculating a vulnerability matching degree based on correlation comparison between the fingerprint features of the third-party libraries and the vulnerability features, and calculating a third-party library security score based on the vulnerability matching degree; obtaining the control flow of the program source code; calculating a source program security score based on the program's input validation, API calls, exception handling, and / or security features in the control flow; and calculating a software security score based on the third-party library security score and the source program security score, and using this score to assess the security of the software. The present invention solves the problem in related technologies of being unable to comprehensively detect security threats to program source code and referenced third-party libraries.
Owner:HANGZHOU DBAPPSECURITY CO LTD

Security APP business logic vulnerability detection method and system, medium and server

The invention belongs to the technical field of application program security detection, and provides a security APP business logic vulnerability detection method and system, a medium and a server, and the method comprises the steps: constructing a standardized time sequence model of a security transaction process, dynamically collecting instruction sequence data during the actual operation of a security APP, comparing an instruction sequence with the standardized time sequence model, and obtaining a security APP business logic vulnerability detection result. And carrying out risk grade division and sorting on the identified abnormal instruction sequence, carrying out simulation verification on an operation path corresponding to the high-risk abnormal sequence, confirming the validity of the business logic vulnerability, and generating a detection report. According to the method, automatic vulnerability identification and verification of the security transaction service full link are realized, the detection coverage rate and efficiency are improved, the service logic vulnerability detection coverage rate can be improved to about 90% or above, the detection efficiency is improved to about 10 times or above of manual work, the artificial scene construction cost is reduced, different broker APP personalized rules can be adapted, and the security transaction service full link vulnerability identification and verification method is suitable for popularization and application. And the method has high expansibility and adaptability.
Owner:CSC FINANCIAL CO LTD

A method, system, electronic device and medium for managing sub-libraries and sub-tables

The present invention discloses a method, system, electronic device, and medium for managing sub-libraries and sub-tables, relating to the field of database management. The method comprises: determining a sub-database to be changed based on parameters that need to be changed in a database; when a backend verifies that a user has access rights to the sub-database, the user inputs a statement; when a backend verifies that the user has query rights to the sub-database, the input statement is parsed; after performing permission verification on the tables, libraries, and statement templates corresponding to the parsed statement, an execution statement is generated based on the parsed statement; and the parameters that need to be changed in the sub-database are changed based on the execution statement. The present invention can perform data updates and data queries on large quantities of homogeneous tables and can improve program security.
Owner:SHANGHAI JUSHUITAN NETWORK TECH CO LTD

Static program analysis method oriented to inter-language interaction behaviors in multi-language program

The invention discloses a static program analysis method for inter-language interaction behaviors in a multi-language program, which comprises the following steps of: constructing a uniform expression model of analysis results of a Java pointer analysis framework and a C pointer analysis framework, and simultaneously modeling inter-language interaction interfaces defined in various Java local interface specifications; the analysis result of the Java pointer analysis framework and the C pointer analysis framework at the inter-language interaction point can be represented by the representation model and perceived by the pointer analysis framework of the other party, so that the pointer analysis framework of the other party can analyze specific inter-language interaction behaviors according to modeling of the inter-language interaction interface. In addition, the method can be used for being combined with a current most advanced pointer analysis framework, and the accuracy and efficiency of inter-language interaction behavior analysis are improved. Through the method, a more complete analysis result is expected to be provided for applications such as program security analysis and defect detection.
Owner:NANJING UNIV

Power measurement terminal application behavior identification method and device based on variational encoder and Gaussian mixture model, and computer equipment

The invention relates to the technical field of application program security management, and provides a power measurement terminal application program behavior identification method and device based on a variational encoder and a Gaussian mixture model, and computer equipment. The method comprises the following steps: judging a variational encoder model of a network and side channel characteristic data when an application program generates a target behavior according to a behavior category to obtain a potential variable; judging a Gaussian mixture model of the network according to the behavior category to obtain the probability that the potential variable belongs to each cluster; when the maximum probability value corresponding to the potential variable is greater than a preset probability threshold value, or the reconstruction error of the variational encoder model is smaller than a preset error threshold value, if the data volume of the cluster corresponding to the maximum probability value is maximum, determining the target behavior as a normal behavior; if the data volume is not maximum, determining the target behavior as a sensitive behavior; and if the maximum probability value is less than a preset probability threshold and the reconstruction error is greater than a preset error threshold, determining the target behavior as a malicious behavior. By adopting the method, the accuracy of behavior recognition is improved.
Owner:GUANGZHOU POWER SUPPLY BUREAU GUANGDONG POWER GRID CO LTD +1

Application program security authentication method and device based on Windows platform

The invention belongs to the technical field of information security, and provides an application program security authentication method and device based on a Windows platform, and the method comprises the steps: obtaining a portable executable PE file corresponding to an application program of the Windows platform; encrypting the PE file, and writing the encrypted PE file into a target resource segment of a preset PE file to obtain a target PE file; running the target PE file, and acquiring and decrypting the encrypted PE file under the condition that the target PE file passes the target authentication to obtain a decrypted file; wherein the target authentication comprises user identity authentication and user authority authentication, or user identity authentication. According to the method, an identity authentication mechanism based on the password technology can be added to the application program of the Windows platform on the premise of zero transformation, relevant requirements of secret evaluation are met, the safety of original PE file identity authentication is improved, and the authentication cost is reduced.
Owner:CHINA ELECTRONICS STANDARDIZATION INST

Program security detection method based on block chain, related equipment and storage medium

The invention discloses a program security detection method based on a block chain, related equipment and a storage medium, the method stores program verification information of each public program in a program management service based on a target block chain, and the program verification information comprises program signature information and a public key of a program development end issuing the public program. The program signature information is obtained by encrypting a program hash value of a public program based on a private key of a program development end, so that after a program use end obtains a target public program from a program management service, corresponding target program verification information is obtained from the target block chain; the method comprises the steps of obtaining a target public program, performing hash calculation on the target public program on the basis of a preset hash function to obtain a to-be-verified program hash value, and performing signature verification processing on the basis of target program verification information and the to-be-verified program hash value to obtain a program security detection result. The reliability of program security detection is improved, and the risk of running malicious programs is reduced.
Owner:TENCENT TECHNOLOGY (SHENZHEN) CO LTD

Static program safety test tool evaluation method, device and equipment

The embodiment of the specification discloses a static program security testing tool evaluation method, device and equipment, the method comprises the following steps: receiving the evaluation request of the static program security testing tool for the preset programming language; based on the evaluation request, the syntax characteristic information of the preset programming language and the information of different dimensions of the sensitivity analysis related to the program analysis ability accuracy of the static program security testing tool are obtained; based on the syntax characteristic information of the preset programming language, a plurality of different first evaluation indexes for the evaluation completeness are constructed, and based on the different dimensions of the sensitivity analysis related to the program analysis ability accuracy, a plurality of different second evaluation indexes for the evaluation accuracy are constructed, based on each evaluation index in the plurality of first evaluation indexes and the plurality of second evaluation indexes, one or more different positive and negative sample pairs are obtained, and the static program security testing tool is respectively evaluated based on the obtained positive and negative sample pairs.
Owner:ZHEJIANG UNIV +1

Baffle program processing method and device, computer device and readable storage medium

The application relates to a baffle program processing method and device, computer equipment and a readable storage medium. The method comprises the following steps: in response to a running request of a baffle program, obtaining a target calling frequency of the baffle program in a target period corresponding to an initiation time of the running request; determining a target confusion strategy of the baffle program according to the target calling frequency; and performing fuzzing processing on the baffle program according to the target confusion strategy, and running the baffle program after the fuzzing processing. The method can improve the security of the baffle program, realize reasonable utilization of resources, and balance system performance.
Owner:ELECTRIC POWER RES INST CHINA SOUTHERN POWER GRID CO LTD +1

PLC program security deployment system and method thereof

The invention discloses a PLC program security deployment system and method. The deployment system comprises a cloud platform, a mobile terminal and a PLC device. The cloud platform receives the deployment request and verifies an operation authority according to a preset role authority, and generates an encryption identifier if the authority passes; the mobile terminal obtains the identity information of the operator through multi-factor authentication, identifies the encrypted identifier, analyzes the encrypted identifier to obtain a deployment instruction, synchronizes the identity information of the operator and the deployment instruction to the cloud platform to verify the execution permission, and triggers the cloud platform to perform environment inspection on the target PLC equipment after the verification is passed; after the inspection is qualified and the operator confirms, the cloud platform issues a program file to the target PLC equipment, and the PLC equipment receives the program file, completes the verification of the program file and executes the PLC program deployment operation according to the deployment instruction; and if the check is unqualified, rejecting deployment and feeding back abnormal information to the cloud platform. According to the method, the safety, traceability and convenience of PLC program deployment are realized, and the deployment efficiency is improved.
Owner:SUZHOU PASTORAL ROBOT CO LTD

An Application Security Isolation and Protection Method and System

The present invention relates to an application program security isolation and protection method, which includes an entrance module, as well as an interception module, a server-side application program module, a database module, and an identity authentication server module on the server side; the above modules are coordinated with each other to perform identity card authentication and intercept and review legal information. The method of the present invention transparently supports various requests externally, extracts metadata information from all requests for unified interception and verification, realizes the filtering and interception of malicious requests and illegal users, and ensures the security of application program data. Moreover, each module in this method is independent of each other, and the update of one module will not affect other modules, with low maintenance costs.
Owner:SHENYANG INST OF COMPUTING TECH CO LTD THE CHINESE ACAD OF SCI

Full-cycle fine-grained program logic consistency protection method and system based on password

The invention relates to the technical field of network security, in particular to a full-cycle fine-grained program logic consistency protection method and system based on passwords, in a program design stage, code values and address offset information of each instruction in a program are extracted, a fixed label corresponding to each instruction is generated by using a cryptographic algorithm, and a verification account book is formed; and when a program runs, extracting a code value and address offset information of a current execution instruction in real time, obtaining a verification label through a cryptographic algorithm, and carrying out matching verification on the verification label and a corresponding fixed label in a verification account book. When a program runs, if a function calling instruction is encountered, a return address of a current function is extracted, and a dynamic label of the return address is generated through a cryptographic algorithm; after function calling is completed, the return address is extracted, a verification label is obtained through cryptographic algorithm calculation, and matching verification is conducted on the verification label and the stored dynamic label. The logic consistency of the full life cycle of the program is effectively protected, malicious tampering is prevented, and the safety and reliability of the program are improved.
Owner:陈艺丹