Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

98 results about "Protocol Status" patented technology

Inter-switch multi-protocol conversion and dynamic routing optimization method and system

The invention relates to an inter-switch multi-protocol conversion and dynamic routing optimization method and system. The method comprises the following steps: carrying out feature analysis processing on routing protocol messages collected by each switch in an interconnection structure, and extracting to obtain a protocol state parameter set comprising protocol type identifiers, path attribute fields and adjacent state information; performing structured semantic mapping on the path attribute field according to the protocol type identifier, and constructing to obtain a standardized path parameter model fusing multiple protocol structure features; and generating a dynamic routing control instruction set for guiding each switch to execute path switching according to a link connection relationship between the standardized path parameter model and the adjacent state information in combination with a path selection strategy associated with the protocol type identifier. By adopting the method, unified routing behavior management of the switch in a multi-protocol environment can be realized.
Owner:SHENZHEN SCODENO TECH CO LTD

Fine-grained security policy enforcement for applications

Embodiments generate state elements based on application requests from a client. The state elements may be enqueued in a state queue associated with an application session for an application requests and the application requests may be forwarded to the application. Application responses from the application may be employed to perform further actions, including: generating message elements based on the application responses such that the message elements may be enqueued in a message queue associated in the application session; determining a portion of the state elements in the state queue that may be associated the message elements; updating the portion of the state elements to advance a protocol state based on the message elements such that the application responses may be communicated to the client.
Owner:DELINEA INC

Malicious traffic message interception and retention method based on threat intelligence

The invention discloses a malicious traffic message interception and retention method based on threat intelligence, and the method comprises the following steps: S1, importing a threat intelligence data set, generating an intelligence label dictionary, and caching the intelligence label dictionary; s2, receiving a network data packet through a traffic mirroring device or an acquisition probe, and aggregating the network data packet into a traffic aggregation object based on a quintuple; s3, modeling and recording a state transition sequence based on a protocol state machine; s4, detecting a state transition sequence by using the information label dictionary, and identifying potential malicious traffic; s5, extracting data messages corresponding to the key nodes to form an extracted message set; s6, grouping according to the information labels and encrypting by using an improved AES symmetric encryption algorithm to generate an encrypted message file; s7, constructing an index data table containing a quintuple, capture time and an information label, and associating the index data table with the encrypted message file; and S8, storing the encrypted message file and the index data table in a separated storage system, and updating the index data table regularly. The method and the device are suitable for a threat-driven encrypted message processing scene.
Owner:GUANGXI POWER GRID CORP

Charging pile test method and device and new energy automobile

The invention provides a charging pile testing method and device, a new energy automobile and electronic equipment, and the method comprises the steps: constructing a corresponding CAPL script according to the testing demands of a charging pile; performing version identification on the CAPL script to obtain a DBC file; defining message logic of the DBC file; dynamically configuring a protocol state machine corresponding to the DBC file after the message logic is defined; and after the dynamic configuration is completed, switching the configuration according to a test requirement, and generating a test report. The method can be applied to charging protocols of multiple versions, is higher in adaptability, improves the fault detection intensity, can be compatible with various different test scenes and test requirements, can dynamically adjust the test path according to the test requirements, and is higher in flexibility and higher in practicability.
Owner:CHINA FAW CO LTD

Automatic use case construction method and system for private protocol test

The invention discloses an automatic use case construction method and system for private protocol testing, and relates to the technical field of communication protocol testing. Comprising the following steps: step 1, identifying a field structure, a state conversion rule and a dependency relationship of a private protocol through traffic sniffing and deep packet analysis; step 2, dynamically generating a test case set covering a normal scene, a boundary scene and an abnormal scene based on a reinforcement learning algorithm in combination with a protocol state machine and a historical test result; and step 3, injecting the generated test flow in the simulation environment, monitoring response data of the target system in real time, calculating and adjusting an evaluation value, and adjusting a generation strategy of the test case according to the value. Through adaptive execution and multi-dimensional anomaly analysis in the simulation environment, the test strategy is adjusted in real time, logic errors, resource leakage and security vulnerabilities are accurately recognized, efficient robustness verification of the private protocol is achieved, and the test efficiency and protocol security are remarkably improved.
Owner:SHANGHAI ANBAN INFORMATION TECH CO LTD

Method for identifying and protecting Teensy virus of mobile hard disk

The invention discloses a Teensy virus identification and protection method for a mobile hard disk, and relates to the technical field of virus identification and protection.The method effectively identifies high-simulation attack equipment through composite equipment fingerprint construction and combination of hardware ripple features and dynamic protocol response, and breaks through the limitation of traditional single feature detection; meanwhile, the protocol state transition probability model adopts hidden Markov chain real-time analysis, microsecond-level protocol switching abnormity is accurately captured, and the problem of missing detection caused by rough time granularity of an existing scheme is solved; in addition, a window context instruction association mechanism binds a system focus state with an HID operation, and blocks a hidden attack chain formed by legal instruction combination; the hierarchical fusing strategy fuses protocol endpoint control and physical layer isolation, so that the availability of a storage function is ensured, meanwhile, attack blocking is realized, and the situation that normal use is influenced due to full-port forbidding in a traditional scheme is avoided.
Owner:WEIMEIO (BEIJING) TECHNOLOGY DEVELOPMENT CO LTD

Multi-Agent-based hierarchical progressive RFC state machine model extraction method

The invention relates to a multi-Agent-based hierarchical progressive RFC state machine model extraction method, belongs to the technical field of network protocol extraction, and solves the problems that RFC document information is difficult to refine when a state machine model is extracted at present, the large model used for extraction is easily influenced by illusion due to the limitation of the large model, and the accuracy and recall rate are difficult to guarantee. Comprising the steps of obtaining an RFC document of a to-be-extracted state machine model and performing structured processing to obtain each RFC document block taking a title as a demarcation point; based on a preset protocol state machine term, recalling a core document block, a supplementary document block and a long tail document block from each RFC document block; extracting an initial state machine model from the core document block, performing review, and optimizing the initial state machine model based on a review result to obtain a reviewed state machine model; and on the basis of the supplementary document block and the long tail document block, performing supplementary optimization on the reviewed state machine model to obtain an RFC state machine model.
Owner:BEIHANG UNIV

Network transmission protocol intrusion detection method and system

The invention relates to the technical field of network security detection, and discloses a network transmission protocol intrusion detection method and system. The method comprises the following steps: acquiring a network transmission protocol data stream, extracting head features and load features of a data packet, and integrating to form an original feature set; the original feature set is classified according to protocol types, different protocol clusters are divided, and corresponding identifiers are marked; constructing a dynamic feature filter based on the protocol cluster identifier, and screening a feature subset associated with the current protocol cluster from the original feature set; inputting the feature subset into a protocol state analysis model, and outputting a protocol state vector and abnormal behavior probability distribution by the model; and generating an intrusion detection result according to the two, and triggering a corresponding defense response instruction. According to the method, different protocol characteristics are adapted through protocol cluster classification and dynamic characteristic screening, accurate identification of protocol intrusion behaviors is realized, and the method can be applied to various scenes depending on a network transmission protocol.
Owner:XI'AN PETROLEUM UNIVERSITY

Intrusion detection method based on boundary sensitive federated expert multi-modal detection

The invention provides an intrusion detection method based on boundary sensitive federated expert multi-modal detection, which comprises the following steps of: splicing, synthesizing and fusing seven types of discriminative characteristics based on original traffic characteristics, designing a multi-modal collaborative attention model MultiModalFusion, dividing the characteristics into four modals, namely a protocol state, a traffic behavior, statistical distribution and a connection relationship, and realizing cross-modal information interaction by utilizing dynamic weight learning. In order to solve the problem of data imbalance, a boundary sensitive condition generator BSGenemator is developed to guide generation of minority class samples through a dynamic boundary strategy in combination with a composite loss function method. And finally, constructing a federal element strategy expert committee, dynamically fusing decisions of four experts by adopting a learnable strategy network, and verifying the characteristic contribution degree through an SHAP interpretable module. And finally, the efficiency of the scheme is verified by using a data set UNSW-NB15, through comparison of multiple schemes, the scheme has significant accuracy, the weighted average F1 score is improved, and a new normal form is provided for a real-time intrusion detection scheme.
Owner:HUAIYIN INSTITUTE OF TECHNOLOGY

Packet data convergence protocol status report transmission

Various aspects of the present disclosure generally relate to wireless communication. In some aspects, a transmitting device may detect a condition associated with a packet data convergence protocol (PDCP) status report transmission. The transmitting device may transmit, based at least in part on detecting the condition, a PDCP status report that indicates a first sequence number corresponding to a first protocol data unit that is not to be transmitted by the transmitting device and that indicates a quantity of sequence numbers corresponding to a quantity of protocol data units beginning with the first protocol data unit that are not to be transmitted by the transmitting device. Numerous other aspects are described.
Owner:QUALCOMM INC

Protocol fuzz testing method and system based on potential relationship between states

The invention belongs to the technical field of network security protocol vulnerability mining, and discloses a protocol fuzz testing method and system based on a potential relationship between states, the method comprises the following steps: in a state modeling stage, tracking directed edges in a tested program state machine to generate a state bitmap, the state bitmap comprising state transition information; in the state selection stage, a state selection problem is modeled as a multi-arm machine optimization problem, and the optimization problem is solved by using an Epsilone-Greedy algorithm and a Thompson sampling algorithm in combination with state transition information. According to the method, the state bitmap is designed to represent the condition of inter-state migration, basic state information is reserved, meanwhile, representation of the state machine is simplified, the mapping relation between the tested protocol state machine and the state bitmap is established, inter-state migration is abstracted into state points in the state bitmap, and therefore the process of constructing and analyzing the tested protocol state machine is simplified.
Owner:Chinese People's Liberation Army Cyberspace Force Information Engineering University

Industrial protocol heterogeneous acceleration system based on FPGA

The invention discloses a field programmable gate array (FPGA)-based industrial protocol heterogeneous acceleration system, which adopts a configurable protocol state table to perform protocol analysis, and can dynamically adjust an analysis rule according to different industrial protocol standards, so that the FPGA-based industrial protocol heterogeneous acceleration system can flexibly process different types of industrial protocols, thereby increasing the use flexibility; meanwhile, a heterogeneous acceleration engine is further arranged, software and hardware with the lowest load in software and hardware units for processing the tasks in the FPGA can be determined according to different task types, and the software and hardware with the lowest load are dispatched for protocol analysis; therefore, efficient processing of the industrial protocol can be realized through cooperative work accelerated by software and hardware; on the basis, different types of industrial protocols can be flexibly processed, efficient acceleration of processing of various industrial protocols can be achieved at the same time, and on the basis, the application scene with the high requirement for the real-time performance of an industrial site can be met, so that the overall stability and reliability of an industrial system can be improved.
Owner:LESHAN NORMAL UNIV +1

Protocol logic vulnerability mining method based on program multi-dimensional variation

The invention discloses a protocol logic vulnerability mining method based on program multi-dimensional variation. The method comprises the following steps: firstly, based on an RFC protocol standard, automatically positioning a buffer write function responsible for writing a message and a state variable used for identifying a protocol state in a program; then, multi-dimensional variation is carried out, including content level variation (field replacement, field multiplexing and field deletion) and sequence level variation (message repetition and message skipping), and a variation message with legal grammar and abnormal semantics is generated; and finally, monitoring state variables of a protocol state machine and an instrumentation program defined based on the RFC standard, detecting the difference of behaviors of a plurality of protocol implementation state machines under the same variation input by using a consistency test method, automatically discovering violation of protocol implementation on the RFC standard, and classifying the violation into logic vulnerabilities. According to the method, typical vulnerabilities such as degradation attacks, repeated extension and missing extension in cryptographic protocol implementation can be automatically mined, and 49 logic problems are found in multiple protocol implementation.
Owner:SOUTHEAST UNIV

SOME / IP protocol vulnerability detection method based on combination of fuzzy test and deep learning model

The invention relates to an SOME / IP protocol vulnerability detection method based on combination of a fuzzy test and a deep learning model, and belongs to the technical field of automobile network security. In order to solve the problems of poor vehicle-mounted private protocol analysis capability, low test case effectiveness and narrow vulnerability coverage of the traditional fuzzy test, the invention provides a closed-loop detection scheme. The closed-loop detection scheme comprises the following steps: firstly, collecting real traffic of a vehicle-mounted Ethernet SOME / IP protocol and preprocessing the real traffic into training data; training a generative adversarial network model by using the valid / invalid test case set, and autonomously learning protocol features; generating a virtual test case with high protocol conformity through the model; and feeding back the optimization model in combination with a secondary fuzzy test and a vulnerability analysis result. According to the method, the problem of reverse analysis of a private protocol is solved, automatic generation and iterative optimization of the test case are realized, and the abnormal triggering rate is remarkably improved; complex scene vulnerabilities such as a protocol state machine and service interaction logic can be deeply mined, and the communication security protection capability of a vehicle-mounted network is improved.
Owner:CHONGQING UNIV OF POSTS & TELECOMM

Adaptive feature fusion intrusion detection method and system for electric power industrial control network

The invention provides a self-adaptive feature fusion intrusion detection method and system for an electric power industrial control network, and the method comprises the steps: enabling the generation of a sample to strictly follow the sequential logic of an industrial control protocol through introducing a protocol state perception dynamic sampling mechanism; multi-modal causal feature extraction is adopted, protocol semantics, equipment fingerprints and causal association features are fused, and the feature discrimination ability is effectively improved; designing a federated residual error enhancement fusion model, and realizing safety cooperative training and heterogeneous data adaptation between distributed nodes; and in combination with deep reinforcement learning and transfer learning, constructing a detection parameter dynamic tuning mechanism. According to the method, various attacks such as DoS attacks, protocol forgery and unauthorized access can be accurately identified, the real-time performance of services is guaranteed, meanwhile, the detection precision is remarkably improved, the false alarm rate is reduced, and the method has high environmental adaptability and can be widely applied to electric power industrial control scenes such as transformer substations and dispatching centers.
Owner:ZHANGZHOU POWER SUPPLY COMPANY STATE GRID FUJIANELECTRIC POWER +1

Computer network intrusion detection method and system based on artificial intelligence

The invention belongs to the technical field of artificial intelligence, and particularly relates to a computer network intrusion detection method and system based on artificial intelligence, and the method comprises the steps: constructing a finite state automaton to carry out the state jump compliance verification of a connection flow, intercepting the illegal flow, only sending the compliance flow into a feature engineering module, and extracting the multi-dimensional behavior features; inputting a deep neural network classification model to determine whether the behavior is an intrusion behavior; according to the technical scheme provided by the invention, the data input to the artificial intelligence model can be ensured to have complete compliance on the protocol level, so that the model is prevented from learning false feature association caused by protocol violation, and the antagonistic attack based on protocol state jump can be effectively resisted on the premise of not depending on adversarial training.
Owner:WEINAN NORMAL UNIV

Some / ip protocol grey box fuzzy test method and system

The invention discloses a some / ip protocol grey box fuzzy test method and system, and the method comprises the steps: calculating a generation probability for each element of each seed sequence in an obtained protocol data packet, calculating a copy probability according to the seed sequence and a corresponding sensitive element sequence, and taking the condition probability of maximizing the sensitive element sequence as a target function, completing the extraction of sensitive elements; taking the ID as an index, and constructing a corpus by the sensitive elements, the relative offset, the weights and the response state codes; and selecting a corresponding corpus from the corpus for a protocol data packet to be mutated according to a protocol state, performing replacement variation by using the sensitive element corresponding to the maximum weight and the relative offset, and completing the fuzzy test by monitoring the execution condition of the test case. The variation strategy is optimized by identifying the sensitive structure of the protocol data packet, the seed generation quality is improved through the structure-sensitive variation strategy, and the fuzzy test efficiency and the vulnerability detection capability are improved.
Owner:SHANDONG POLICE ACAD

Industrial control private protocol vulnerability mining method based on protocol analysis

The invention discloses an industrial control private protocol vulnerability mining method based on protocol analysis. The method comprises the steps of 1, preprocessing industrial control protocol flow data; and 2, analyzing the target protocol by using the byte change characteristics and the heuristic rule. And 3, generating a test case of the target protocol by using the analysis specification. And 4, reconstructing a protocol state machine by using the state conversion track of the flow, and guiding the protocol to reach a target state for testing. And 5, tracking the state of the detected target and monitoring and positioning the triggered vulnerability through a network. According to the method, the analysis accuracy of the private protocol specification can be effectively improved, the test case acceptance rate, the test target anomaly rate and the state coverage rate in the fuzzy test process are remarkably improved, and meanwhile, more protocol states can be efficiently tested under the condition of the same number of test cases so as to mine more potential vulnerabilities in the protocol.
Owner:BEIJING UNIV OF TECH

High-interaction sip honeypot system based on phased interaction control

This invention discloses a highly interactive SIP honeypot system based on phased interactive control, comprising: a message receiving module for receiving external SIP requests; a SIP interactive control module supporting multiple interaction modes and generating corresponding responses according to the current configuration mode; a session state machine module for maintaining the SIP session protocol state; a phase switching control module for maintaining phase state variables and dynamically selecting the interaction mode according to preset trigger conditions; and a recording and statistics module for recording request behavior characteristics, interaction logs, and switching logs. This invention achieves runtime schedulable management of interactive capabilities, enabling low-resource-consumption recording of scanning behavior and deep trapping of advanced attacks and collection of complete attack chain data, providing reliable data support for the detection of encrypted malicious traffic.
Owner:SUN YAT SEN UNIV

An edge intelligence-based low-altitude communication data anomaly detection system and method

PendingCN122293551ADigital dataAlgorithm
This invention belongs to the field of electronic digital data processing technology, specifically relating to a low-altitude communication data anomaly detection system and method based on edge intelligence. The system parses protocol fields from the raw bitstream of the low-altitude communication link layer, extracts type identifiers and payload lengths to construct a protocol state machine transition matrix, and utilizes a Long Short-Term Memory (LSTM) network to extract state transition probability sequence features. Geographically adjacent edge nodes are set as micro-federated learning groups. Each node, after training using local features, only uploads network gating weight parameters to its neighboring nodes for weighted aggregation to update its local model. An alarm is triggered when the real-time state transition probability sequence deviates from the normal transition matrix and exceeds a preset topology threshold. This invention can identify protocol state machine logic errors and transition anomalies, reducing the amount of communication data required for collaborative model updates between edge nodes.
Owner:SHENZHEN UNICAIR COMM TECH CO LTD

A VR signal direct connection system and method based on multi-protocol adaptive matching

The application discloses a VR signal direct connection system and method based on multi-protocol adaptive matching, wherein the VR signal direct connection system comprises a signal receiving unit used for receiving signals of different frequency bands; a protocol decoding unit used for performing protocol decoding on the transmitted signals; an LSTM protocol prediction model used for generating a protocol priority queue and transmitting the generated protocol priority queue to a dynamic protocol loading unit; the dynamic protocol loading unit is used for judging whether to switch protocols according to signal quality conditions and the generated protocol priority queue, and if yes, transmitting the protocol state after switching to an FPGA dynamic partition; the FPGA dynamic partition is used for receiving the protocol state transmitted by the dynamic protocol loading unit and the protocol data transmitted by the protocol decoding unit; a signal processing module is used for receiving the protocol state and the protocol data transmitted by the FPGA dynamic partition, processing the received data information, and generating the content displayed on a VR device.
Owner:HANGZHOU FUYANG XINGSHU ZHIJING TECHNOLOGY DEVELOPMENT CO LTD

Multi-protocol adaptation system and method for actuator internet of things

The invention relates to the technical field of industrial internet-of-things automatic control, and discloses an actuator internet-of-things multi-protocol adaptation system and method.The method comprises the steps that a protocol module constructs a state machine model for each protocol adapter, cross-protocol state collaboration and abnormal event release are achieved through tense logic rule verification, and a resource module receives abnormal events and sends the abnormal events to a server; the method comprises the following steps: dynamically updating a global resource constraint graph, analyzing an optimal resource reallocation scheme and an atomic task sequence, deconstructing the task sequence into a pi-calculation concurrent process network by applying a reconstruction module, recombining the process network and mapping the recombined process network into a cross-protocol instruction set to drive an executor, and finally, executing the Pi-calculation concurrent process network. Full-link adaptation from protocol layer state consistency guarantee and resource layer dynamic optimization scheduling to application layer process flexible reconstruction is realized, and the reliability and response efficiency of a multi-protocol actuator system in a complex industrial environment are improved.
Owner:SHANGHAI HAIWEI IND CONTROL CO LTD

An IoT Fuzzy Testing Method Based on LLM Guidance and FSM Dynamic Inference

This invention discloses an IoT fuzzing method based on LLM-guided and FSM dynamic inference, belonging to the field of IoT network security and software testing technology. Addressing the problems of low coverage and inaccurate state machine inference in current IoT protocol fuzzing, this invention first constructs an initial FSM by combining IoT protocol specifications and captured traffic data. Then, it generates a large number of test cases through mutation of seed test cases for fuzzing testing. Features are extracted from device responses, and state identification is performed by calculating similarity. When a new state appears, the FSM and state fingerprint database are updated. When coverage becomes a bottleneck, LLM-guided path inference is used to generate extended sub-FSMs and test cases, which are then executed. The FSM is then corrected based on the test results. This invention enables high-precision automated construction of IoT protocol state FSMs, improving test coverage and enhancing the efficiency and accuracy of vulnerability discovery.
Owner:BEIJING UNIV OF POSTS & TELECOMM

Network flow generation and restoration method based on protocol constraint

PendingCN121814685Aavoid splittingConducive to describing structural characteristicsTransmissionHigh level techniquesDiffusion networkInternet traffic
The invention discloses a network flow generating and repairing method based on protocol constraint. The method comprises the following steps: analyzing an original traffic capture file, extracting basic features through stream-level recombination and session segmentation, and mapping a continuous time sequence and a discrete protocol field to a uniform feature space; and on the basis, constructing a diffusion type network flow generation model to capture a statistical attribute and time sequence dependency relationship of the network flow. In the generating or repairing process, a protocol state machine is constructed, protocol constraint is introduced in the reverse denoising stage, the sampling process is constrained through a legality guiding mechanism, and protocol logic violation in the generating process is avoided. And finally, through feature inverse mapping and virtual protocol stack state maintenance, reconstructing to obtain network flow data which meets a communication protocol specification and can be correctly analyzed by a real protocol stack. According to the method, the generation and repair of the network traffic can be realized under a unified framework, and the correctness of a result in protocol semantics is ensured.
Owner:NANJING TECH UNIV

Network protocol program parallel fuzzy test method and device and electronic equipment

The invention provides a network protocol program parallel fuzzy test method and device and electronic equipment, and relates to the technical field of computers. The network protocol program parallel fuzzy test method comprises the following steps: acquiring a state model of a to-be-tested protocol program with a directed graph structure; according to a plurality of state nodes of the state model and a data model associated with the output operation of each state node, generating a plurality of protocol state paths carrying path variation calculation amount weights; according to the number of test examples of the protocol program to be tested and the path variation calculation amount weight of each protocol state path, determining the test task amount weight of each test example; and according to the test task load weight of each test instance and the similarity between the protocol state paths, allocating the protocol state paths to the corresponding test instances. According to the invention, fuzz testing can be efficiently and accurately carried out on the network protocol program.
Owner:TSINGHUA UNIVERSITY

Isolation device for protocol, access control method, equipment and medium

The invention discloses a protocol isolation device, an access control method, equipment and a medium, and relates to the technical field of industrial network boundary security, the device comprises an extranet host system, an isolation switching unit and an intranet host system which are all physical modules; wherein each of the extranet host system and the intranet host system comprises a message analysis module, a protocol state module, an access strategy module and an intelligent scheduling module; and strategies such as time-sharing double ferrying, protocol state tracking, a dynamic strategy and intelligent scheduling are designed, and through coordination work of the strategies, a protocol isolation and control scheme which can meet the high-speed data interaction requirement of the industrial Internet of Things and is stable and safe in performance is provided.
Owner:ELECTRIC POWER RES INST CHINA SOUTHERN POWER GRID CO LTD

Network defense detection method and device, equipment, storage medium and product thereof

The invention discloses a network defense detection method, device and equipment, a storage medium and a product thereof, and relates to the technical field of network security, the method is applied to a coprocessor module arranged in a terminal, the coprocessor module is used for network security testing, and the method comprises the following steps: monitoring a network service enabling event of the terminal, loading a corresponding attack script according to the started service to carry out a network security test; in the testing process, comparing a first transfer path of the protocol state expected by the attack script with a second transfer path of the protocol state actually executed by the main processor, and judging whether the first transfer path is consistent with the second transfer path or not; and if the first transfer path is not consistent with the second transfer path, determining that an exception exists in the test, and controlling a communication module of the terminal to repair the corresponding security hole. That is, the whole process from vulnerability identification to communication layer repair can be completed without depending on external network interaction, so that the autonomous defense capability of the Internet of Things terminal in a complex network environment is enhanced.
Owner:PANASONIC APPLIANCES (CHINA) CO LTD

Database test method and device, electronic equipment and storage medium

The invention discloses a database testing method and device, electronic equipment and a storage medium, and the method comprises the steps: obtaining to-be-processed traffic of a target database, and determining protocol feature information corresponding to at least one data packet in the to-be-processed traffic; generating at least one to-be-injected exception script based on the protocol feature information of each data packet and a protocol state machine corresponding to the target database; determining a communication protocol layer corresponding to each abnormal script to be injected, and injecting to obtain an abnormal test model; and generating a test report according to a comparison result of the output data of the abnormal test model and the target comparison data corresponding to the target database. The corresponding exception test model is constructed according to the protocol interaction characteristics of the database, and the coverage rate of the test scene to the exception condition in the real network is improved by adding the exception scene in the exception test model, so that the security test effect is performed on the target database in a targeted manner.
Owner:TIANJIN NANKAI UNIV GENERAL DATA TECH

Risk protection method and device for data acquisition and electronic equipment

The invention provides a risk protection method and device for data acquisition and electronic equipment, and the method comprises the steps: obtaining a plurality of original messages of a data acquisition node, carrying out the security enhancement processing of each original message, obtaining a reinforced message flow, carrying out the multi-dimensional risk detection of the reinforced message flow, obtaining a risk score, and carrying out the risk protection of the data acquisition node. The multi-dimensional risk detection comprises the step of carrying out risk detection on at least two of a protocol state layer, a time sequence behavior layer and a semantic content layer; according to the invention, the security of the original message is enhanced, so that the risk of sensitive data leakage is reduced; multi-dimensional risk detection is performed through a protocol state layer, a time sequence behavior layer, a semantic content layer and the like, so that combined attacks can be identified in a cross-dimension manner, and the security of data acquisition is improved.
Owner:CISDI INFORMATION TECH CO LTD