Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

286 results about "Security alarm" patented technology

A security alarm is a system designed to detect intrusion – unauthorized entry – into a building or other area. Security alarms are used in residential, commercial, industrial, and military properties for protection against burglary (theft) or property damage, as well as personal protection against intruders. Security alarms in residential areas show a correlation with decreased theft. Car alarms likewise help protect vehicles and their contents. Prisons also use security systems for control of inmates.

Multi-source heterogeneous network security alarm aggregation noise reduction method, system and device

The invention discloses a multi-source heterogeneous network security alarm aggregation noise reduction method, system and device. The method comprises the following steps: step 1, constructing a network security alarm ontology model; step 2, standardization processing of multi-source alarm; 3, performing dynamic alarm aggregation based on an entity relationship; 4, multi-level alarm noise reduction and intelligent study and judgment are carried out; according to the method, deep standardization is carried out on multi-source heterogeneous alarms through the network security alarm ontology model, and a data semantic gap is eliminated; a dynamic aggregation strategy based on a core entity and a relationship is adopted, related alarms surrounding the same core entity in a specific time window are aggregated into aggregated alarms, the order of magnitude of the number of the alarms is reduced, and a complete attack scene description is formed; a three-layer progressive noise reduction mechanism is adopted, false alarms and low-value alarms are eliminated, and high credibility of output safety events is guaranteed; automatic conversion from massive original alarms to a small number of high-value security events is realized, and the security operation response speed and decision quality are improved.
Owner:北京国御网络安全技术有限公司

Automated Multi-Phase Investigation of Security Incident Alerts Using a Large Language Model (LLM) with Converging Dialogue

ActiveUS20250307419A1Platform integrity maintainanceOrganizational contextComputerized system
Automated multi-phase investigation of security incident alerts using a Large Language Model (LLM) with converging dialogue. A computerized system receives a Security Alert Message pertaining to a possible security-related incident pertaining to an organization. The system automatically evaluates whether the Security Alert Message is either (I) a False Positive security alert message or (II) a True Positive security alert message, by performing an iterative multi-phase converging process in which the LLM evaluates at least: (i) the content of that Security Alert Message, and (ii) the meta-data of that Security Alert Message, and (iii) organizational context that is related to that Security Alert Message. An iterative process is performed by the LLM, which utilizes an Agent Module to fetch additional context information from organizational sources. The LLM re-updates the Risk Score and re-evaluates the Risk Score until convergence to a decision.
Owner:VARONIS SYSTEMS INC

Electric power AI safety detection model optimization method and system fusing attribution quantization and confrontation correction

The invention discloses an electric power AI security detection model optimization method and system fusing attribution quantification and adversarial correction. The optimization method comprises the following steps: step 1, carrying out structured semantic representation on heterogeneous security alarms of an electric power network; 2, performing model decision logic analysis based on hybrid attribution quantization; step 3, automatically diagnosing decision prejudice based on domain knowledge masks; step 4, constructing an adversarial sample generated based on an anti-fact text; and 5, performing closed-loop fine adjustment and optimization on the attribution regularization model. According to the method, the interpretable ability of large model decision analysis, the root cause positioning ability of misinformation and the autonomous repair optimization ability are improved, the transparency and credibility of model decision are improved, the model misinformation caused by environmental influence is reduced, and the efficiency of model autonomous correction is improved.
Owner:STATE GRID HENAN INFORMATION & TELECOMM CO

Cross-network collaborative security alarm noise reduction method based on security federal learning

The invention relates to a cross-network collaborative security alarm noise reduction method based on security federal learning, and belongs to the field of network security. Comprising the steps that a server prepares and distributes a large model injected with personalized and global parameter modules; the client performs fine adjustment based on local alarm data and only uploads gradient update of the global parameter module; the server dynamically divides a network layer into a low-conflict layer and a high-conflict layer by calculating the gradient conflict degree of each client on each network layer of the global module; the server only aggregates the low-conflict layers to update the global model and distributes the update back to the client, while the client retains its locally trained low-conflict layer. To-be-detected alarms are input into the client large model to be analyzed and processed, and accurate alarms and disposal suggestions are fed back to the data set for continuous optimization after the result is audited by experts. According to the method, client drift is relieved, and the noise reduction accuracy and individuation effect of the model on heterogeneous data are remarkably improved while data privacy is protected.
Owner:YUNNAN PROVINCIAL BIG DATA CO LTD

Power metering system network security situation analysis method and system based on big data

The invention provides an electric power metering system network security situation analysis method and system based on big data, and relates to the technical field of electric power system information security. According to the method, network traffic, system logs, security alarms, asset information, vulnerability records and external threat intelligence are collected, a security data lake is constructed, and security situation factors are extracted; outputting an anomaly detection result and a threat classification result by using the unsupervised anomaly detection model and the supervised threat classification model; calculating an asset security risk value and an overall security risk value by combining the vulnerability severity and the asset importance, and generating an overall security index, an attack threat level and a vulnerability level; and a time sequence prediction model is further constructed based on the network security situation indexes, and future situation prediction and security early warning are realized. According to the invention, comprehensive perception, accurate analysis and active defense of the network security situation can be realized.
Owner:HARBIN INSTITUTE OF TECHNOLOGY (SHENZHEN) (INSTITUTE OF SCIENCE AND TECHNOLOGY INNOVATION HARBIN INSTITUTE OF TECHNOLOGY SHENZHEN)

Network security alarm method and device, electronic equipment and storage medium

The invention provides a network security alarm method and device, electronic equipment and a storage medium, and belongs to the technical field of network security, and the method comprises the steps: obtaining security logs, configuration information and asset importance levels of all security equipment in a network; performing association analysis on the configuration information, and determining attack surface data of each IP point in the network; performing noise reduction and correlation analysis on the security log to obtain processed log information, matching the processed log information with a preset feature library, and filtering alarms of normal service features and alarms of misreported attack features to obtain filtered alarm data; inputting the attack surface data, the asset importance level and the alarm data into a large language model to generate an alarm priority sequence; and executing an automatic response based on the alarm data, the alarm priority sequence and a configured response script. According to the invention, the problem of high false alarm rate of network security alarm in the prior art can be solved.
Owner:BEIJING ANBOTONG TECH CO LTD

Low-energy-consumption intelligent door and window safety alarm method and system based on environment perception

The invention relates to the field of intelligent door and window alarm, in particular to a low-energy-consumption intelligent door and window safety alarm method and system based on environmental perception. The invention discloses a low-energy-consumption intelligent door and window safety alarm system based on environmental perception. The system comprises a correlation calculation module, an initial score calculation module, a monitoring alarm module and a monitoring frequency updating module. According to the method, the system energy efficiency is obviously optimized through a dual periodic scoring mechanism and a monitoring frequency dynamic adjustment strategy; establishing a basic energy consumption baseline based on an initial score generated by a user characteristic parameter, and generating a second importance score to accurately quantify a risk value of each scene in combination with deviation degree analysis and time sequence correction of short-period environment monitoring data; the dynamic regulation and control mode enables the equipment to maintain an ultra-low power consumption state in a risk-free period, and compared with a traditional fixed frequency, the monitoring scheme can significantly reduce energy consumption, and is especially suitable for long-term stable operation of a battery-powered intelligent window control device.
Owner:SHANDONG HUADA DOOR WINDOW & CURTAIN WALL CO LTD

Intelligent security alarm method and system based on smart park

The invention relates to the technical field of intelligent security and protection, and discloses an intelligent security and protection alarm method and system based on an intelligent park. The method comprises the following steps: acquiring original security and protection data by using sensing equipment arranged in a smart park; performing standardization and redundancy elimination processing on the original security and protection data, dividing safety areas of the park through a pattern recognition algorithm, calculating a load intensity index of each area, and generating a security and protection situation summary; according to the security situation summary, a heuristic search algorithm is adopted to determine alarm trigger parameter initial values including detection sensitivity and alarm intervals, and a basic alarm parameter group is generated; performing nonlinear correction on the basic alarm parameter group, and outputting an environment perception alarm parameter group; training the historical security data set by adopting a neural network model, and analyzing the interaction between the load and the threat to obtain a threat diffusion model; and comparing the threat diffusion model with the real-time security data points, performing difference measurement, reconstructing alarm trigger logic according to a measurement result, and completing autonomous regulation and control of security and protection of the smart park.
Owner:SHANDONG MODERN BIG DATA TECH CO LTD

Attack chain restoration method and system based on large language model and traditional AI model

The invention provides an attack link restoration method and system based on a large language model and a traditional AI model, and effectively solves the problem that attack link restoration is incomplete and inaccurate when a current attack link restoration scheme faces complex factors such as network address translation. The method comprises the following steps: acquiring an attack semantic knowledge base containing an attack context knowledge matrix, wherein the knowledge base is generated by processing an attack framework, a security log and a traceability report by a generative large model; obtaining an asset access relation graph generated by analyzing the metadata of the target network infrastructure by the large model and reasoning in combination with an attack semantic knowledge base; regularly acquiring security alarm logs in a first time window and scoring, and acquiring context logs if the security alarm logs exceed a threshold value; based on a time sequence diagram attention network model, determining the confidence degree that edges in an asset access relation graph corresponding to logs containing access pairs in the alarm logs and the context logs belong to attack links; and performing sub-graph extraction in the atlas to obtain candidate sub-graphs, and then determining a target attack link.
Owner:ULTRAPOWER SOFTWARE +1

Timing sequence post-synchronization quantum key extraction method based on classical information fusion

A time sequence post-synchronization quantum key extraction penetration test method comprises the following steps: A) under the condition of penetration test, a QKD system operates normally, and a sending end and a receiving end smoothly complete key distribution; b) the man-in-the-middle selects an initial original key exchange period to establish synchronization and correlation so as to realize clock synchronization with a receiver; c) analyzing quantum bit error rate information obtained from a public channel by a man-in-the-middle, deducing a corresponding relation between a receiver detector and each quantum state, and establishing a mapping model of the quantum states and bit values; d) determining a quantum state type responded by the receiver in each response time slot in a subsequent original key exchange period by the middleman in combination with path information obtained by other sub penetration tests; and E) the intermediary obtains a final key which is the same as the two communication parties by implementing an error correction and privacy amplification process, the quantum bit error rate between the intermediary and the sender is maintained at a relatively low level and is lower than a security threshold, and a security alarm is not triggered in a penetration test process.
Owner:NAT UNIV OF DEFENSE TECH

Systems and methods for real-time generation and execution of computer-executable investigative queries in a cybersecurity event detection and response platform

A system, method, and computer-implemented method includes generating a security alert for a subscriber, executing an automated investigation protocol for the security alert, obtaining, in response to executing a first plurality of computer-executable investigation queries and a second plurality of computer-executable investigation queries, a corpus of investigation findings data indicative of whether the security alert corresponds to a security threat or a benign security alert, and displaying, using a graphical user interface, the security alert in association with the corpus of investigation findings data.
Owner:EXPEL INC

Safety alarm noise reduction method based on rule and large model

The invention relates to a security alarm noise reduction method based on rules and a large model, which belongs to the field of network security and comprises the following steps of: collecting security alarm data and security logs and preprocessing the security alarm data and the security logs; constructing a dynamic comprehensive rule knowledge base comprising a screening rule base and a plug-in knowledge base, and periodically updating the dynamic comprehensive rule knowledge base; selecting an open-source large model of the security field, using the open-source data set of the security field and historical security alarm data, and utilizing a distillation technology to finely adjust a noise reduction small model; a knowledge base driven periodic fine tuning and dynamic knowledge injection double-path coordination mechanism is adopted to improve the capability of the noise reduction small model; and finally, realizing efficient and accurate alarm noise reduction based on the screening rule base and the noise reduction small model. According to the invention, the efficiency and accuracy of security alarm noise reduction are effectively improved, and an efficient, accurate and intelligent alarm noise reduction method is provided for the field of network security.
Owner:YUNNAN PROVINCIAL BIG DATA CO LTD

Systems and methods of safety incident monitoring and response with artificial intelligence

Systems and methods for facilitating electronic safety alert communications by a safety alert management system are disclosed herein. A method includes receiving an electronic safety alert for a specific safety event from a user electronic device via a safety alert application, the safety alert including at least one user message from a user associated with the user device. The method includes initiating an electronic chat session between the user and the safety agent attending the safety management application and, for at least one user message received at the safety management application, determining a reply message to send to the user device in response to the at least one user message. In embodiments, a machine learning model is used to analyze the user message and determine one or more recommended reply messages to display to the agent. A method for training a safety chat language model in a safety alert management system is also disclosed.
Owner:RAPIDSOS

Automated multi-phase investigation of security incident alerts using a large language model (LLM) with converging dialogue

ActiveUS12530469B2Platform integrity maintainanceOrganizational contextComputerized system
Automated multi-phase investigation of security incident alerts using a Large Language Model (LLM) with converging dialogue. A computerized system receives a Security Alert Message pertaining to a possible security-related incident pertaining to an organization. The system automatically evaluates whether the Security Alert Message is either (I) a False Positive security alert message or (II) a True Positive security alert message, by performing an iterative multi-phase converging process in which the LLM evaluates at least: (i) the content of that Security Alert Message, and (ii) the meta-data of that Security Alert Message, and (iii) organizational context that is related to that Security Alert Message. An iterative process is performed by the LLM, which utilizes an Agent Module to fetch additional context information from organizational sources. The LLM re-updates the Risk Score and re-evaluates the Risk Score until convergence to a decision.
Owner:VARONIS SYSTEMS INC

Automatic incident identification, investigation, and next-step prediction

The disclosed techniques automatically identify cyber-security attacks and predict attack next steps. Descriptions of previously observed cyber-attack campaigns are decomposed into attack campaign steps. Real-time security incident signals are generated by cybersecurity software. Attack campaigns are identified by mapping attack campaign steps to security incident signals. Custom-generated telemetry queries are executed to determine if a missing attack campaign step occurred. A machine learning model generates embeddings for attack campaign steps, security incident signals, and telemetry query responses. A security incident signal or a telemetry query response matches an attack campaign step when their embeddings are within a defined distance. A security alert may be raised when most or all of the attack campaign steps of a particular attack campaign are matched. Attack campaign steps that are not matched to security incident signals or telemetry query results are predicted as attack next steps.
Owner:MICROSOFT TECHNOLOGY LICENSING LLC

Remote security alarm system combining video monitoring and intrusion detection identification technology

The invention belongs to the technical field of security supervision, and particularly relates to a remote security alarm system combining video monitoring and intrusion detection identification technology, which comprises a multispectral dynamic frame acquisition module, a hierarchical feature enhancement fusion module, a space-time correlation intrusion behavior identification module, an intrusion risk quantitative evaluation module and a security supervision end. Monitoring data acquisition is performed through a multispectral dynamic frame acquisition module, a fusion feature map is generated through a layered feature enhancement fusion module to improve the feature identification degree of an intrusion target, intrusion identification fine judgment is performed through time-space correlation comprehensive judgment and introduction of an environment interference coefficient, and the accuracy of effective intrusion identification is improved. A risk assessment system is constructed from three core dimensions of target threat degree, intrusion position importance and behavior intensity, so that a security supervision terminal can clearly master the risk degree of an intrusion event, the system has the capabilities of adapting to a complex environment, accurately identifying intrusion and scientifically assessing risks, and the reliability and supervision efficiency of remote security alarm are effectively improved.
Owner:KEZHUN TESTING TECHNOLOGY RESEARCH INSTITUTE (SHANXI) CO LTD

Security alert meta-analysis for identifying causally related evidence of cyberattacks

A security alert meta-analysis (SAMA) system is disclosed capable of identifying causally related evidence of a cyberattack in a computing environment. In embodiments, the system builds a security data graph from security alerts generated by other security monitoring services. The security data graph links related entities (e.g. users and resources) in the computing environment and the entities to their associated security alerts. Edges in the graph are filtered based on edge weights to identify sub-graphs that represent clusters of causally related evidence probative of attacks. The evidence clusters are presented to analysts to be investigated further. In embodiments, the meta-analysis process is implemented as periodic jobs executed on a cluster of worker nodes. Advantageously, the disclosed system is able to filter through large volumes of alerts to reduce false positives, and group related alerts, possibly from different monitoring services, so that they can be investigated together.
Owner:AMAZON TECH INC

Big data platform-oriented multi-dimensional high-value target mining and protecting method and system

The invention relates to a mining and protecting method and system for a multi-dimensional high-value target of a big data platform, and the method comprises the steps: collecting multi-source heterogeneous data from a plurality of platform data sources, carrying out the information extraction, and forming a fusion triple comprising entity type feature data, attribute type feature data and relation type feature data, constructing a dynamically updated platform structure map based on the fusion triad; performing asset function value evaluation, asset topology importance evaluation and attacker accessibility evaluation on each type of nodes in the platform structure map to obtain a corresponding comprehensive risk score, and identifying a high-value target set; and in response to a security alarm event, associating alarm information with the platform structure map to position an alarm node, thereby extracting a serialized context sub-graph from the platform structure map in combination with the high-value target set, performing attack intention recognition, and outputting an attack intention report. According to the method, a security protection system with perspectiveness and semantic understanding capability can be provided for a big data platform.
Owner:XIDIAN UNIV

Safety alarm noise reduction and automatic disposal method based on intelligent agent

The invention provides a security alarm noise reduction and automatic disposal method based on an intelligent agent, and belongs to the technical field of network security. Comprising the steps of collecting and preprocessing security alarm data, and constructing a noise reduction rule base, a noise reduction knowledge base and an alarm processing knowledge base; a noise reduction small model is finely adjusted by using an open source large model, a noise reduction knowledge base and a knowledge distillation technology, and a script generation large model is finely adjusted by using an alarm disposal knowledge base based on a general reasoning large model; performing two-stage noise reduction on the safety alarm by using a noise reduction rule base and a noise reduction small model to obtain an effective alarm; generating a corresponding disposal script through the large script generation model; creating a task allocation agent and a disposal agent; and after the feasibility of the script is manually judged, the task distribution agent delivers the script to the corresponding disposal agent for execution, and the similarity and success rate of historical cases are fused to assist in judging a subsequent disposal mode. According to the invention, the efficiency and accuracy of security alarm processing are effectively improved.
Owner:YUNNAN PROVINCIAL BIG DATA CO LTD

Re-encryption near field communication method and safety door lock

The invention relates to the field of Internet of Things security and intelligent access control, and particularly discloses a re-encryption near field communication method and a security door lock, and the method comprises the following steps: S1, in a near field communication establishment stage, carrying out equipment bidirectional authentication by adopting a national cipher SM4 algorithm, and generating a dynamic session key; s2, in a data transmission stage, dynamically switching an AES-256 or DES encryption algorithm based on the signal strength to ensure the communication security; s3, when abnormal operation is detected, triggering an SM3 hash algorithm to generate a security alarm fingerprint, and interrupting a current communication link; according to the invention, through dynamic combination encryption of a national cryptographic algorithm and AES / DES, a security protection system adaptive to a communication environment is constructed, and bidirectional authentication of equipment is realized by adopting an SM4 algorithm in a near field communication establishment stage, so that identity credibility is ensured; in the data transmission stage, the encryption strength is intelligently switched according to the real-time signal strength, so that the communication reliability in a weak signal environment is guaranteed, and the data confidentiality in a strong signal environment is enhanced.
Owner:陈雪峰

Safety alarm investigation system and method based on large language model

The invention relates to the technical field of artificial intelligence, in particular to a security alarm investigation system and method based on a large language model, and the system comprises a data processing module which comprises a data collection unit used for collecting security alarm data; the model training module is connected with the data processing module and comprises a model generation unit which is used for dividing the suspicious security event data into a training set and a verification set and training an initial model to generate a large language model; the agent module is connected with the model training module and comprises an interaction unit which is used for interacting with a user through a safety agent so as to output interaction information; and the execution module is respectively connected with the data processing module, the model training module and the agent module, and is used for determining the calling frequency of the large language model according to the increasing rate of the number of rounds of interaction between the security agent and the user. According to the invention, the accuracy of safety alarm investigation is improved.
Owner:RUI AN ZHIYUAN (BEIJING) INFORMATION TECH CO LTD

Thermal management system fault processing method and device and related product

The invention discloses a thermal management system fault processing method, a thermal management system fault processing device and a related product. And under the condition that the fault alarm signal is monitored, fault information corresponding to the fault alarm signal is input to the influence evaluation model. The influence evaluation model can carry out objective, automatic and standardized influence grade evaluation on a fault from three dimensions of a refrigeration / heating function of the thermal management system, acquisition of parameters of a preset type and a preset safety alarm triggering condition, and finally obtains an influence grade and executes a control strategy corresponding to the influence grade. And a closed-loop automatic process from fault monitoring to grade judgment to strategy execution is formed. And through refined grading and differentiated fault-tolerant strategies, the functions of the thermal management system can be maintained to the maximum extent on the premise of safe operation of the thermal management system so as to improve the availability of the thermal management system. And meanwhile, the method can be popularized and applied only by defining the influence of each fault on three dimensions according to requirements, has high universality and is suitable for various thermal management systems.
Owner:HEFEI ZERO ENTROPY TECH CO LTD

Security system for generating artificial intelligence (AI) insights about security alerts

A security system may receive, without a submission of a user query, a model response from a large language model, where the model response includes structured data generated by the large language model using a plurality of security alerts. A security system may render an interface on a computing device using the structured data, where the interface displays information about a security insight event detected by the large language model using the plurality of security alerts, and the interface identifies a portion of the plurality of security alerts as related to the security insight event.
Owner:ELASTIC TECHNOLOGIES (US) INC

Scenic region cultural relic and historic site intelligent protection and monitoring system based on edge calculation

The invention discloses a scenic area cultural relic and historic site intelligent protection and monitoring system based on edge calculation, and relates to the technical field of cultural relic intelligent monitoring, and the system comprises a multi-mode sensing module which is used for being deployed in the surrounding environment and body of a cultural relic and historic site and comprises a temperature and humidity sensor, a micro-vibration sensor, an optical image sensor and an ultraviolet intensity sensor; the edge computing node terminal is used for receiving the acquired data of the multi-mode sensing module, performing environment monitoring, image processing and vibration spectrum analysis according to the acquired data, and generating a state monitoring signal; the cloud collaboration platform is connected with the edge computing node terminal through a communication link and is used for data storage and analysis; and the safety alarm terminal is used for receiving the state monitoring signal from the edge computing node terminal and triggering a corresponding action. According to the method, the limitation of a traditional cultural relic protection means is broken, real-time and intelligent cultural relic and historic site protection work is realized, and the protection effect is remarkably improved.
Owner:GUANGXI LVFA TECH CO LTD

Context-aware audit log intelligent analysis method based on large language model

The invention provides a context-aware audit log intelligent analysis method based on a large language model, and the method comprises the steps: collecting an access audit log of a server cluster, carrying out the standardization processing of an operation description in the log, and generating structured log data; performing semantic analysis on the operation description in the structured log data by utilizing a large language model, extracting an implicit behavior pattern and generating a semantic vector; constructing a multi-dimensional feature vector in combination with context information such as user identity, resource attributes and behavior statistics in an operation time window; automatically generating an access control rule through a rule generation model based on the multi-dimensional feature vector, and verifying the robustness of the rule by simulating an attack scene; and deploying the access control rule passing the verification to a target system, and outputting corresponding security alarm information. According to the embodiment of the invention, the detection precision and dynamic adaptability of audit log analysis can be improved, and the false alarm rate and the manual maintenance cost are reduced.
Owner:JINAN INSPUR DATA TECH CO LTD

Safety alarm noise reduction method and system based on data weaving technology

The invention relates to the technical field of data noise reduction, and discloses a safety alarm noise reduction method and system based on a data weaving technology, and the method comprises the steps: building a unified logic data view based on a data weaving architecture; deploying an AI-driven data intelligent agent component system, automatically identifying and adapting a changing API and a new data source, and fusing metadata, threat intelligence and infrastructure operation state information; constructing an attack chain panorama and a behavior causal chain model; a semantic noise reduction algorithm, time sequence clustering analysis and a confidence scoring mechanism are adopted to perform de-duplication alarm, false alarm identification and low-risk event filtering on the security alarm; and alarm de-duplication and priority adjustment are carried out to generate a linkage processing strategy. According to the invention, the problems of alarm flooding, high false alarm rate, low processing efficiency and the like in the existing security alarm system are solved.
Owner:BEIJING HUIERTE TECH CO LTD

Lithium battery energy storage system safety protection method based on multi-dimensional state monitoring

The invention relates to the technical field of safety protection, in particular to a lithium battery energy storage system safety protection method based on multi-dimensional state monitoring, and the method comprises the steps: collecting parameters in real time; judging a to-be-determined module; determining a risk module; determining an abnormal module; adjusting an abnormal threshold value; and sending a safety alarm. Multi-dimensional parameters are subjected to combined monitoring and quantitative analysis in a time window, a causal and synchronism judgment mechanism among the parameters is established, abnormal candidates are screened out according to charge state values and duration, then a temperature threshold value is derived according to a current temperature correspondence table triggered by parallel current, temperature deviation and duration are calculated, and the accuracy of the temperature deviation is improved. And meanwhile, the sliding fluctuation correlation between the abnormal proportion and the vibration frequency is taken as an adjustment criterion, and the initial duration threshold value is relaxed according to the deviation when the correlation is obviously increased, so that the problems of inaccurate battery abnormal identification and response delay caused by single parameter monitoring and fixed threshold value judgment are effectively solved.
Owner:GUANGZHOU YINGXUN POWER NEW ENERGY CO LTD

Systems and methods for real-time generation and execution of computer-executable investigative queries in a cybersecurity event detection and response platform

A system, method, and computer-implemented method includes generating a security alert for a subscriber, executing an automated investigation protocol for the security alert, obtaining, in response to executing a first plurality of computer-executable investigation queries and a second plurality of computer-executable investigation queries, a corpus of investigation findings data indicative of whether the security alert corresponds to a security threat or a benign security alert, and displaying, using a graphical user interface, the security alert in association with the corpus of investigation findings data.
Owner:EXPEL INC

Network security threat detection method and device, storage medium and processor

The invention discloses a network security threat detection method and device, a storage medium and a processor. According to the scheme, real-time alarm data are acquired; based on a white list rule base, filtering the real-time alarm data, and performing semantic clustering de-duplication on the filtered real-time alarm data to obtain real-time alarm data after semantic clustering de-duplication; and performing context prompt generation and attack chain reasoning on the real-time alarm data after semantic clustering and duplicate removal by using a large language model to obtain a network security threat detection result corresponding to the real-time alarm data. Compared with the prior art that the manual verification alarm consumes a long time, the processing efficiency is low, a large language model API is directly called to analyze the full-amount alarm, the API calling cost per month is very high due to the fact that a huge amount of safety alarm data is used, and sustainable operation and large-scale deployment of the system are seriously limited, the method has obvious advantages.
Owner:AGRICULTURAL BANK OF CHINA

Security alarm processing method and device, equipment and storage medium

The invention discloses a security alarm processing method and device, equipment and a storage medium, and relates to the technical field of network security, and the method comprises the steps: carrying out the data preprocessing of multi-source heterogeneous data, and obtaining security alarm data; identifying the security alarm data through an alarm identification model, and determining an alarm type and a threat level; performing graph construction on the security alarm data through a graph database to generate a security knowledge graph; performing association analysis on the security knowledge graph to obtain attack chain information; and carrying out risk research and judgment on the attack chain information according to the alarm type and the threat level to obtain a comprehensive risk level. According to the method, the security alarm data is identified through the alarm identification model, so that the detection capability of novel attacks can be improved; and meanwhile, alarm correlation analysis is carried out in combination with the constructed security knowledge graph, and potential attack chains and complex attack behaviors are effectively identified, so that the alarm can be deeply analyzed, and the hazard degree of the alarm can be accurately judged.
Owner:STATE GRID HUBEI ELECTRIC POWER INFORMATION & TELECOMMUNICATION COMPANY +1