Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

8 results about "Risk vulnerability" patented technology

A vulnerability is a weakness or gap in our protection efforts. Risk – The potential for loss, damage or destruction of an asset as a result of a threat exploiting a vulnerability. ... Risk is a function of threats exploiting vulnerabilities to obtain, damage or destroy assets. Thus, threats (actual, conceptual, or inherent) may exist, but if there are no vulnerabilities then there is little/no risk.

Method and device for constructing network security operating system, electronic equipment and storage medium

ActiveCN121887549AArtificial lifeSecuring communicationOperational systemTrusted computing base
The invention belongs to the field of network security, and relates to a method and a device for constructing a network security operating system, electronic equipment and a storage medium, and the method comprises the following steps: constructing an autonomously controllable improved microkernel infrastructure; based on the microkernel infrastructure, constructing a full-stack layered security control computing architecture base; constructing intelligent agent components, and deploying a multi-intelligent agent collaborative protection component system; integrating trusted computing and an integrity measurement verification system; performing dynamic adaptation and execution of multiple security policies; and a standardized safety evaluation and adaptive optimization closed loop is established. A trusted computing base is cut from a design source, so that the probability of occurrence of high-risk vulnerabilities is reduced; the real-time defense that the threat is changed and the strategy is changed is realized, and the blind area of the static strategy in resisting the unknown threat is made up; the malicious codes can be blocked before running, and the post passive situation that traditional security software only depends on a feature library for searching and killing is broken; and the contradiction between security capability solidification and threat dynamic evolution is fundamentally solved.
Owner:SHENZHEN Y& D ELECTRONICS CO LTD

Enterprise-level three-party dependent package security management and control system and method

The invention discloses an enterprise-level three-party dependency package security management and control system and method, and relates to the technical field of software supply chain security, and the enterprise-level three-party dependency package security management and control system comprises the following modules: a timed task scheduling module, an external network package pre-scanning module, a private service package monitoring module, a dependency graph construction module, a product management and control module and a notification display module. By establishing an external network packet pre-scanning mechanism, security scanning is performed and a blocking list is generated before a dependent packet enters an enterprise private server, and introduction of a packet containing high-risk vulnerabilities is blocked from the source; meanwhile, through the continuous monitoring of the private server package and the construction of the dependency relationship graph, the vulnerability discovery and the accurate positioning of the influence range of the stored dependency package are realized; and finally, performing hierarchical management and control on the affected products based on vulnerability levels, and realizing timely transmission and situation visualization of risk information through a notification display module. According to the invention, full-life-cycle safety protection from an external network source to internal products of an enterprise is realized, and the safety management level and risk response efficiency of the dependent package of the enterprise are effectively improved.
Owner:CHINA FAW CO LTD +1

An AI-based application code vulnerability detection and repair method in a low-code platform

The application relates to an AI-based application code vulnerability detection and repair method in a low-code platform, and the application comprises the following steps: collecting and aligning multi-modal context signals, generating a business intention anchor vector by using a lightweight intention encoder, fusing vulnerability features through cross-modal attention, searching a dynamic template library, and constructing an intention constraint repair space; a three-element utility function is used to realize multi-objective trade-off of safety, continuity and business intention; finally, a repair suggestion code and an explanation text consistent with the business constraint are output, and the intention understanding capability is optimized through user feedback loop. The application can significantly improve the script security and business continuity of the low-code platform, automatically generate vulnerability repair suggestions consistent with the business intention of the developer, promote the dynamic improvement of the self-adaptation capability of the platform, and significantly reduce the risk of unintended behavior caused by automatic modification while ensuring the effective elimination of high-risk vulnerabilities.
Owner:GUANGZHOU ZHUORUI DIGITAL TECHNOLOGY CO LTD

Wind-resistant safety guarantee method for segmented hoisting of stiffening girder of large-span offshore suspension bridge

This invention discloses a method for ensuring wind resistance safety during the segmented hoisting of stiffening girders for long-span suspension bridges at sea. It relates to the field of wind resistance technology for hoisting, including pre-construction measures based on bridge design parameters and construction organization plans. By establishing a wind resistance safety assurance system, and in actual use, creating a digital twin model covering the entire construction process and conducting multi-condition simulations in advance, this method can identify wind-induced risk vulnerabilities at each stage from hoisting to closure, transforming passive response into proactive anticipation. This greatly ensures the safety of personnel, equipment, and the structure. Simultaneously, refined management reduces unnecessary work stoppages, helps seize construction windows during limited typhoon breaks, shortens the overall construction period, facilitates real-time monitoring of each stage, and allows for the management, visualization, and storage of wind resistance safety assurance data and corresponding analysis results. Furthermore, it facilitates wind resistance safety assurance management through internet cloud control, improving the level of intelligence in wind resistance safety assurance management.
Owner:XIAMEN UNIV OF TECH

A ship cyber security protection system and method

The application provides a kind of ship network security protection system and method, it is related to ship network security technical field, the system includes storage module, detection management module, selection module and auditing and output module, the ship network security protection system and method provided by the application adopt double confirmation mechanism, the access or change of ship network key parameters is confirmed twice using automated vulnerability scanning tool, additional confirmation step and security requirement are increased, the defense capability of system to potential security threat is significantly improved, it is helpful to prevent hacker or malicious user from executing illegal operation by forging identity or exploiting system vulnerability, so as to protect the safe and stable operation of ship network system, and adopt priority sequencing rule, improve vulnerability processing efficiency, and high-risk vulnerability is processed preferentially to help reduce the exposure of system, reduce the possibility of being attacked by attacker, to improve the overall security of system, protect critical data and business from being violated.
Owner:SHANGHAI ZHONGCHUAN SDT-NERC CO LTD

A method for verifying penetration test results by comparing them with vulnerability databases

This invention relates to the field of network testing technology and discloses a method for comparing and verifying penetration test results with a vulnerability database. The method includes the following steps: performing attack chain topology analysis on the original penetration test results, extracting each attack node and the path dependencies between nodes, and constructing a directed acyclic graph (DAG) of the attack chain; for each attack node in the DAG, retrieving a set of hit candidates from the vulnerability database using a three-layer progressive comparison method. The purpose of this method is to address the problem that existing comparison and verification methods forcibly decompose penetration test results into discrete vulnerability entries, severing the real node path dependencies and attack chain topology. This results in an inability to accurately quantify the actual threat of vulnerabilities in the actual attack path by combining real-world environmental conditions and topological locations, leading to the underestimation of high-risk vulnerabilities on critical paths and inaccurate remediation priorities.
Owner:WUHAN YULIAN INFORMATION TECH CO LTD

Ship network security protection system and method

The invention provides a ship network security protection system and method, and relates to the technical field of ship network security, and the system comprises a storage module, a detection management module, a selection module and an auditing and outputting module. An automatic vulnerability scanning tool is used for carrying out secondary confirmation on access or change of ship network key parameters, additional confirmation steps and security requirements are added, the defense capability of the system for potential security threats is remarkably improved, hackers or malicious users can be prevented from executing illegal operations by counterfeiting identities or utilizing system vulnerabilities, and the safety of the system is improved. Therefore, safe and stable operation of the ship network system is protected, a priority ranking rule is adopted, vulnerability processing efficiency is improved, high-risk vulnerabilities are processed preferentially, the exposed surface of the system is reduced, the possibility of being used by attackers is reduced, the overall safety of the system is improved, and key data and services are protected from being damaged.
Owner:SHANGHAI ZHONGCHUAN SDT-NERC CO LTD

A method and system for full-link penetration testing of critical grid equipment

The application provides a kind of full-link penetration test method and system of power grid key equipment, it is related to electric power information security technical field.The method comprises: the layered analysis of the network link of power grid key equipment is carried out to the network security of equipment, determines the potential threat source of each network level corresponding key equipment;Based on the potential threat source, call the pre-constructed full-link vulnerability module resource pool to carry out the full-link penetration test of power grid key equipment;Each network level includes master station layer, communication layer and terminal layer;The full-link vulnerability module resource pool is obtained by modular encapsulation of the vulnerability exploit chain information formed between each network level by high-risk vulnerability module;High-risk vulnerability module is screened out based on the modular penetration test of different services on each network level corresponding key equipment.The application solves the problem that the existing security vulnerability mining has insufficient detection capability and incomplete vulnerability mining when facing new network attacks.
Owner:CHINA ELECTRIC POWER RESEARCH INSTITUTE CO LTD