Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

17 results about "Program security" patented technology

A security program is a documented set of your company's information security policies, procedures, guidelines, and standards. Your security program should provide a roadmap for effective security management practices and controls.

Implementation method and device of programmable API security gateway

ActiveCN115913750BSoftware engineeringProgram security
This invention discloses a method and apparatus for implementing a programmable API security gateway. The method includes: identifying API interface characteristics and automatically programming policy templates for the API interfaces based on these characteristics; detecting security events of the API interfaces and automatically programming security policy templates for the API interfaces based on these security events; and monitoring the operational status of the API interfaces and automatically adjusting the flow control and security policies associated with the API interfaces. This method and apparatus improve the maintenance efficiency of API interfaces and reduce operational costs.
Owner:CHINA UNITECHS

Binary program vulnerability mining method, device and system based on symbolic execution and taint analysis and medium

The invention provides a binary program vulnerability mining method, device and system based on symbolic execution and taint analysis and a medium, and the method comprises the steps: disassembling a target program, extracting a control flow graph (CFG) and a data flow graph (DFG), recording a node state through a hash table, and generating a feature representation through nonlinear transformation; performing simulation execution based on CFG, DFG and feature representation, recording variable symbol values to obtain path conditions, and recursively solving constraints to generate path mapping; marking input as taint data, recursively calculating a propagation path to generate a taint flow diagram, and determining a taint state after sensitive operation; checking whether the stains are subjected to sensitive operation or not, and if the influence of integral formula calculation exceeds a threshold value, judging that potential vulnerabilities generate a candidate set; and calculating grades through a risk assessment formula, and generating a report containing positions, types, grades and repair suggestions. The method combines symbolic execution and taint analysis, can comprehensively and accurately detect vulnerabilities, has remarkable precision and efficiency advantages, and is suitable for complex program security analysis.
Owner:HUBEI CENT CHINA TECH DEV OF ELECTRIC POWER

An application software development test system with real-time vulnerability detection

The application belongs to the technical field of application software development test, and discloses an application software development test system with real-time vulnerability detection, which comprises a code real-time collection module, a multi-dimensional vulnerability detection module, a vulnerability accurate positioning module, a vulnerability risk quantitative evaluation module, a dynamic repair guidance module, a data storage module, a visual interaction module and an iterative optimization module, and each module cooperates to form a whole-process closed-loop vulnerability detection and management and control system. The application software development test system with real-time vulnerability detection is adopted, real-time capture, accurate positioning, risk evaluation and dynamic repair suggestion output of the vulnerability are realized, and the software development test efficiency and application program security are improved.
Owner:BEIJING JIAXINYUAN TECHNOLOGY CO LTD

A processor chip branch prediction target buffer security enhancement method and electronic device

The application provides a processor chip branch prediction buffer security strong method and an electronic device. The method comprises: a security domain private key generation and application method, dividing a program security domain and generating two private security keys for each security domain, and ensuring that randomization seeds adopted by different security domains are irrelevant; a structure design of a branch prediction buffer with a label domain and a data domain separated, which is combined with a branch prediction buffer skew lookup and update mechanism to realize a security branch prediction buffer skew randomization lookup and update mechanism within a system life cycle, and the structure design of the branch prediction buffer with the label domain and the data domain separated is combined to realize security within the system life cycle.
Owner:SOUTHEAST UNIV

Code execution method and device, and storage medium

The application discloses a code execution method and device and a storage medium. The application relates to the technical field of program security, and the method comprises the following steps: performing abstract syntax tree conversion on to-be-executed code to obtain a tree-shaped code structure; checking each tree node in the tree-shaped code structure to obtain checking information, adjusting the tree-shaped code structure according to the checking information, and obtaining an adjusted tree-shaped code structure; generating target execution code according to the adjusted tree-shaped code structure; and executing the target execution code in a restricted environment, wherein the restricted environment refers to a code execution environment after a detection function is modified according to a preset restricted object list. Through the application, the problem that the code security checking method in the prior art is not accurate enough and the security of execution code in a system is low, thereby leading to poor system stability, is solved.
Owner:INDUSTRIAL AND COMMERCIAL BANK OF CHINA

Application security risk detection method, device, equipment, medium and product

The application relates to the technical field of artificial intelligence, and provides an application program security risk detection method, device, equipment, medium and product, the application program security risk detection method comprises the following steps: obtaining an application program to be identified; inputting the application program to be identified into a preset identification model to obtain a detection result output by the preset identification model; the preset identification model is obtained by training data of an original application program installation package; the preset identification model comprises multiple intelligent agents working respectively, and the intelligent agents are used for executing different function tasks, wherein the function tasks comprise task scheduling, data analysis and result decision. Through the above mode, the intelligent level and performance index of the identification model can be significantly improved, so that the accuracy of the security risk detection result of the application program is improved.
Owner:CHINA MOBILE GROUP ZHEJIANG +3

Application program security control method and device, equipment, medium and product

The invention discloses an application program safety control method and device, equipment, a medium and a product. The method comprises the steps of obtaining a screenshot image and corresponding user interface structure information when a user operates a current application program; based on the screenshot image and the user interface structure information, using a preset first large language model to perform user behavior analysis to determine whether the user has a high-risk behavior; and if the user has the high-risk behavior, triggering safety early warning. According to the invention, the high-risk behavior of the user can be accurately identified and early warned, and the risk identification precision and adaptability are effectively improved.
Owner:CHINA MOBILE INTERNET CO LTD +1

Windows platform-based application security authentication method and device

The application belongs to the technical field of information security, and provides a kind of application program security authentication method and device based on Windows platform, the method includes: obtaining the portable executable PE file corresponding to the application program of Windows platform;PE file is encrypted, and the encrypted PE file is written into the target resource segment of preset PE file, to obtain target PE file;Run target PE file, and under the condition that target PE file passes target authentication authentication, obtain encrypted PE file and decrypt, to obtain decrypted file;Wherein, target authentication authentication includes user identity authentication and user authority authentication, or user identity authentication.The method can realize the identity authentication mechanism based on password technology to the application program of Windows platform under the premise of zero modification, meet the relevant requirements of secret evaluation, improve the security of original PE file identity authentication and reduce the authentication cost.
Owner:CHINA ELECTRONICS STANDARDIZATION INST

Vulnerability feature recognition method and device based on abnormal object, equipment and medium

The invention discloses a vulnerability feature recognition method and device based on an abnormal object, equipment and a medium, and relates to the field of interactive application program security testing, and the method comprises the steps: creating a throwable abnormal object at a vulnerability trigger point; judging version information of the current Java development tool, calling a Java language access interface to generate a first identification code if the version of the Java development tool is 1.8 or below, and generating a second identification code by acquiring a field in a stack backtracking field of the abnormal object capable of being thrown if the version of the Java development tool is 1.8 or above; and if the version of the Java development tool is 1.8 or below, forming a vulnerability feature code by the first identification code and the context information. According to the main technical scheme and the effects, the operation performance is remarkably improved, the system resource overhead is reduced, the performance interference of the IAST Agent on a main service system in a high-concurrency environment in the version JDK1.9 and above is greatly reduced, and the feasibility of production environment deployment is enhanced.
Owner:HANGZHOU MORESEC TECH CO LTD

Data identity recognition for semiconductor devices

Systems, apparatuses, and methods related to data identity recognition for semiconductor devices are described. A system includes a host and a memory device coupled to the host via an interconnect bus. The host includes a host security manager configured to encrypt data of a command, perform a memory integrity check, allow access to memory of a memory device corresponding to an address of a command based on which entity associated with the host sent the command, generate security keys, program security keys into the memory device, program encryption ranges, or any combination thereof. The memory device includes a memory encryption manager and a memory device security manager. The memory device security manager is configured to detect whether a command was sent from a trusted domain of the host or non-trusted domain of the host and identify which entity associated with the host initiated the command.
Owner:MICRON TECHNOLOGY INC

Program encryption method and device, storage medium and program product

The invention provides a program encryption method and device, a storage medium and a program product, relates to the technical field of computers, and can improve the problem of program leakage and ensure the security of a program. Acquiring a public key in the key pair and a source code of the application program, and compiling the source code by using network assembly to obtain an original byte code; the key pair is the same as a key pair in a second device, and the second device is a device for deploying the application program; generating a symmetric key based on the public key, encrypting the original byte code by using the symmetric key to obtain an encrypted byte code, and encrypting the symmetric key by using the public key to obtain an encrypted symmetric key; and rewriting the code section in the original byte code to generate a rewritten byte code of which the function section is the same as that of the original byte code. Function code logic in a code section of the rewritten byte code meets a function statement in a function section; and writing the encrypted byte code, the decryption logic of the encrypted byte code and the encrypted symmetric key into the self-defined section of the rewritten byte code to obtain an encrypted program package.
Owner:CHINA CONSTRUCTION BANK +1

Software security assessment method, system and readable storage medium

ActiveCN115906094BPlatform integrity maintainanceThird partyProgram security
The present invention discloses a software security assessment method, system, and readable storage medium. The method includes the following steps: extracting fingerprint features of third-party libraries in software delivery files; obtaining vulnerability information disclosed by the third-party libraries and extracting vulnerability features; calculating a vulnerability matching degree based on correlation comparison between the fingerprint features of the third-party libraries and the vulnerability features, and calculating a third-party library security score based on the vulnerability matching degree; obtaining the control flow of the program source code; calculating a source program security score based on the program's input validation, API calls, exception handling, and / or security features in the control flow; and calculating a software security score based on the third-party library security score and the source program security score, and using this score to assess the security of the software. The present invention solves the problem in related technologies of being unable to comprehensively detect security threats to program source code and referenced third-party libraries.
Owner:HANGZHOU DBAPPSECURITY CO LTD

Security APP business logic vulnerability detection method and system, medium and server

The invention belongs to the technical field of application program security detection, and provides a security APP business logic vulnerability detection method and system, a medium and a server, and the method comprises the steps: constructing a standardized time sequence model of a security transaction process, dynamically collecting instruction sequence data during the actual operation of a security APP, comparing an instruction sequence with the standardized time sequence model, and obtaining a security APP business logic vulnerability detection result. And carrying out risk grade division and sorting on the identified abnormal instruction sequence, carrying out simulation verification on an operation path corresponding to the high-risk abnormal sequence, confirming the validity of the business logic vulnerability, and generating a detection report. According to the method, automatic vulnerability identification and verification of the security transaction service full link are realized, the detection coverage rate and efficiency are improved, the service logic vulnerability detection coverage rate can be improved to about 90% or above, the detection efficiency is improved to about 10 times or above of manual work, the artificial scene construction cost is reduced, different broker APP personalized rules can be adapted, and the security transaction service full link vulnerability identification and verification method is suitable for popularization and application. And the method has high expansibility and adaptability.
Owner:CSC FINANCIAL CO LTD

Power measurement terminal application behavior identification method and device based on variational encoder and Gaussian mixture model, and computer equipment

The invention relates to the technical field of application program security management, and provides a power measurement terminal application program behavior identification method and device based on a variational encoder and a Gaussian mixture model, and computer equipment. The method comprises the following steps: judging a variational encoder model of a network and side channel characteristic data when an application program generates a target behavior according to a behavior category to obtain a potential variable; judging a Gaussian mixture model of the network according to the behavior category to obtain the probability that the potential variable belongs to each cluster; when the maximum probability value corresponding to the potential variable is greater than a preset probability threshold value, or the reconstruction error of the variational encoder model is smaller than a preset error threshold value, if the data volume of the cluster corresponding to the maximum probability value is maximum, determining the target behavior as a normal behavior; if the data volume is not maximum, determining the target behavior as a sensitive behavior; and if the maximum probability value is less than a preset probability threshold and the reconstruction error is greater than a preset error threshold, determining the target behavior as a malicious behavior. By adopting the method, the accuracy of behavior recognition is improved.
Owner:GUANGZHOU POWER SUPPLY BUREAU GUANGDONG POWER GRID CO LTD +1

Static program safety test tool evaluation method, device and equipment

The embodiment of the specification discloses a static program security testing tool evaluation method, device and equipment, the method comprises the following steps: receiving the evaluation request of the static program security testing tool for the preset programming language; based on the evaluation request, the syntax characteristic information of the preset programming language and the information of different dimensions of the sensitivity analysis related to the program analysis ability accuracy of the static program security testing tool are obtained; based on the syntax characteristic information of the preset programming language, a plurality of different first evaluation indexes for the evaluation completeness are constructed, and based on the different dimensions of the sensitivity analysis related to the program analysis ability accuracy, a plurality of different second evaluation indexes for the evaluation accuracy are constructed, based on each evaluation index in the plurality of first evaluation indexes and the plurality of second evaluation indexes, one or more different positive and negative sample pairs are obtained, and the static program security testing tool is respectively evaluated based on the obtained positive and negative sample pairs.
Owner:ZHEJIANG UNIV +1

Baffle program processing method and device, computer device and readable storage medium

The application relates to a baffle program processing method and device, computer equipment and a readable storage medium. The method comprises the following steps: in response to a running request of a baffle program, obtaining a target calling frequency of the baffle program in a target period corresponding to an initiation time of the running request; determining a target confusion strategy of the baffle program according to the target calling frequency; and performing fuzzing processing on the baffle program according to the target confusion strategy, and running the baffle program after the fuzzing processing. The method can improve the security of the baffle program, realize reasonable utilization of resources, and balance system performance.
Owner:ELECTRIC POWER RES INST CHINA SOUTHERN POWER GRID CO LTD +1

PLC program security deployment system and method thereof

The invention discloses a PLC program security deployment system and method. The deployment system comprises a cloud platform, a mobile terminal and a PLC device. The cloud platform receives the deployment request and verifies an operation authority according to a preset role authority, and generates an encryption identifier if the authority passes; the mobile terminal obtains the identity information of the operator through multi-factor authentication, identifies the encrypted identifier, analyzes the encrypted identifier to obtain a deployment instruction, synchronizes the identity information of the operator and the deployment instruction to the cloud platform to verify the execution permission, and triggers the cloud platform to perform environment inspection on the target PLC equipment after the verification is passed; after the inspection is qualified and the operator confirms, the cloud platform issues a program file to the target PLC equipment, and the PLC equipment receives the program file, completes the verification of the program file and executes the PLC program deployment operation according to the deployment instruction; and if the check is unqualified, rejecting deployment and feeding back abnormal information to the cloud platform. According to the method, the safety, traceability and convenience of PLC program deployment are realized, and the deployment efficiency is improved.
Owner:SUZHOU PASTORAL ROBOT CO LTD