Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

9 results about "Program security" patented technology

A security program is a documented set of your company's information security policies, procedures, guidelines, and standards. Your security program should provide a roadmap for effective security management practices and controls.

Implementation method and device of programmable API security gateway

ActiveCN115913750BSoftware engineeringProgram security
This invention discloses a method and apparatus for implementing a programmable API security gateway. The method includes: identifying API interface characteristics and automatically programming policy templates for the API interfaces based on these characteristics; detecting security events of the API interfaces and automatically programming security policy templates for the API interfaces based on these security events; and monitoring the operational status of the API interfaces and automatically adjusting the flow control and security policies associated with the API interfaces. This method and apparatus improve the maintenance efficiency of API interfaces and reduce operational costs.
Owner:CHINA UNITECHS

Binary program vulnerability mining method, device and system based on symbolic execution and taint analysis and medium

The invention provides a binary program vulnerability mining method, device and system based on symbolic execution and taint analysis and a medium, and the method comprises the steps: disassembling a target program, extracting a control flow graph (CFG) and a data flow graph (DFG), recording a node state through a hash table, and generating a feature representation through nonlinear transformation; performing simulation execution based on CFG, DFG and feature representation, recording variable symbol values to obtain path conditions, and recursively solving constraints to generate path mapping; marking input as taint data, recursively calculating a propagation path to generate a taint flow diagram, and determining a taint state after sensitive operation; checking whether the stains are subjected to sensitive operation or not, and if the influence of integral formula calculation exceeds a threshold value, judging that potential vulnerabilities generate a candidate set; and calculating grades through a risk assessment formula, and generating a report containing positions, types, grades and repair suggestions. The method combines symbolic execution and taint analysis, can comprehensively and accurately detect vulnerabilities, has remarkable precision and efficiency advantages, and is suitable for complex program security analysis.
Owner:HUBEI CENT CHINA TECH DEV OF ELECTRIC POWER

An application software development test system with real-time vulnerability detection

The application belongs to the technical field of application software development test, and discloses an application software development test system with real-time vulnerability detection, which comprises a code real-time collection module, a multi-dimensional vulnerability detection module, a vulnerability accurate positioning module, a vulnerability risk quantitative evaluation module, a dynamic repair guidance module, a data storage module, a visual interaction module and an iterative optimization module, and each module cooperates to form a whole-process closed-loop vulnerability detection and management and control system. The application software development test system with real-time vulnerability detection is adopted, real-time capture, accurate positioning, risk evaluation and dynamic repair suggestion output of the vulnerability are realized, and the software development test efficiency and application program security are improved.
Owner:BEIJING JIAXINYUAN TECHNOLOGY CO LTD

Code execution method and device, and storage medium

The application discloses a code execution method and device and a storage medium. The application relates to the technical field of program security, and the method comprises the following steps: performing abstract syntax tree conversion on to-be-executed code to obtain a tree-shaped code structure; checking each tree node in the tree-shaped code structure to obtain checking information, adjusting the tree-shaped code structure according to the checking information, and obtaining an adjusted tree-shaped code structure; generating target execution code according to the adjusted tree-shaped code structure; and executing the target execution code in a restricted environment, wherein the restricted environment refers to a code execution environment after a detection function is modified according to a preset restricted object list. Through the application, the problem that the code security checking method in the prior art is not accurate enough and the security of execution code in a system is low, thereby leading to poor system stability, is solved.
Owner:INDUSTRIAL AND COMMERCIAL BANK OF CHINA

Application program security control method and device, equipment, medium and product

The invention discloses an application program safety control method and device, equipment, a medium and a product. The method comprises the steps of obtaining a screenshot image and corresponding user interface structure information when a user operates a current application program; based on the screenshot image and the user interface structure information, using a preset first large language model to perform user behavior analysis to determine whether the user has a high-risk behavior; and if the user has the high-risk behavior, triggering safety early warning. According to the invention, the high-risk behavior of the user can be accurately identified and early warned, and the risk identification precision and adaptability are effectively improved.
Owner:CHINA MOBILE INTERNET CO LTD +1

Data identity recognition for semiconductor devices

Systems, apparatuses, and methods related to data identity recognition for semiconductor devices are described. A system includes a host and a memory device coupled to the host via an interconnect bus. The host includes a host security manager configured to encrypt data of a command, perform a memory integrity check, allow access to memory of a memory device corresponding to an address of a command based on which entity associated with the host sent the command, generate security keys, program security keys into the memory device, program encryption ranges, or any combination thereof. The memory device includes a memory encryption manager and a memory device security manager. The memory device security manager is configured to detect whether a command was sent from a trusted domain of the host or non-trusted domain of the host and identify which entity associated with the host initiated the command.
Owner:MICRON TECHNOLOGY INC

Security APP business logic vulnerability detection method and system, medium and server

The invention belongs to the technical field of application program security detection, and provides a security APP business logic vulnerability detection method and system, a medium and a server, and the method comprises the steps: constructing a standardized time sequence model of a security transaction process, dynamically collecting instruction sequence data during the actual operation of a security APP, comparing an instruction sequence with the standardized time sequence model, and obtaining a security APP business logic vulnerability detection result. And carrying out risk grade division and sorting on the identified abnormal instruction sequence, carrying out simulation verification on an operation path corresponding to the high-risk abnormal sequence, confirming the validity of the business logic vulnerability, and generating a detection report. According to the method, automatic vulnerability identification and verification of the security transaction service full link are realized, the detection coverage rate and efficiency are improved, the service logic vulnerability detection coverage rate can be improved to about 90% or above, the detection efficiency is improved to about 10 times or above of manual work, the artificial scene construction cost is reduced, different broker APP personalized rules can be adapted, and the security transaction service full link vulnerability identification and verification method is suitable for popularization and application. And the method has high expansibility and adaptability.
Owner:CSC FINANCIAL CO LTD

Baffle program processing method and device, computer device and readable storage medium

The application relates to a baffle program processing method and device, computer equipment and a readable storage medium. The method comprises the following steps: in response to a running request of a baffle program, obtaining a target calling frequency of the baffle program in a target period corresponding to an initiation time of the running request; determining a target confusion strategy of the baffle program according to the target calling frequency; and performing fuzzing processing on the baffle program according to the target confusion strategy, and running the baffle program after the fuzzing processing. The method can improve the security of the baffle program, realize reasonable utilization of resources, and balance system performance.
Owner:ELECTRIC POWER RES INST CHINA SOUTHERN POWER GRID CO LTD +1

PLC program security deployment system and method thereof

The invention discloses a PLC program security deployment system and method. The deployment system comprises a cloud platform, a mobile terminal and a PLC device. The cloud platform receives the deployment request and verifies an operation authority according to a preset role authority, and generates an encryption identifier if the authority passes; the mobile terminal obtains the identity information of the operator through multi-factor authentication, identifies the encrypted identifier, analyzes the encrypted identifier to obtain a deployment instruction, synchronizes the identity information of the operator and the deployment instruction to the cloud platform to verify the execution permission, and triggers the cloud platform to perform environment inspection on the target PLC equipment after the verification is passed; after the inspection is qualified and the operator confirms, the cloud platform issues a program file to the target PLC equipment, and the PLC equipment receives the program file, completes the verification of the program file and executes the PLC program deployment operation according to the deployment instruction; and if the check is unqualified, rejecting deployment and feeding back abnormal information to the cloud platform. According to the method, the safety, traceability and convenience of PLC program deployment are realized, and the deployment efficiency is improved.
Owner:SUZHOU PASTORAL ROBOT CO LTD