Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

16 results about "Security analyst" patented technology

Security framework matrix visualizations for notable events

Techniques are described for generating visualizations of security framework information (such as, e.g., MITRE ATT&CK® information) displayed in connection with notable events detected by a data intake and query system. Data intake and query systems, SIEM systems, and other applications often provide user interfaces that display detected occurrences of incidents, sometimes referred to as “notable events,” within users' information technology (IT) environments. A data intake and query system is described herein that is capable of identifying notable events, assigning tactic and technique information to notable events (and optionally to associated risk objects), and causing display of tactic and technique visualizations which are intuitive and customizable, provide ready access to relevant documentation, and follow a format with which security analysts are familiar.
Owner:CISCO TECHNOLOGY INC

Holographic flow monitoring method and system based on AI and BI

The invention discloses a holographic flow monitoring method and system based on AI and BI, and relates to the technical field of network security monitoring. The method comprises the steps of flow collection and data processing, realization of multi-dimensional feature extraction, multi-model detection and dynamic decision by an AI engine, realization of trend, region and situation analysis by a BI engine, realization of anomaly detection based on a behavior baseline, and realization of AI detection result optimization and triggering of BI cross-dimension analysis by an adaptive weight algorithm. The holographic flow monitoring system is constructed through big data driving and fusion of an AI big model, millisecond-level real-time analysis of a security data flow is realized, immediate response of emergency events such as 0day attacks and the like is met, static rule limitation is broken through, the detection accuracy of unknown threats and APT attacks is improved, an AI analysis result and BI visualization capability are fused, and the system has a good application prospect. Multi-dimensional insight of the traffic situation is realized; low-latency interactive query is provided, and ad hoc data exploration of security analysts is supported.
Owner:SHENZHEN Y& D ELECTRONICS CO LTD

Quantifying satisfaction of security features of cloud software systems

A method of quantifying the satisfaction of security requirements is provided via characterizing a security feature; matching the security feature to a security metric; computing a quantification score that indicates the exploitability of a system to which the security feature is applied; and outputting the quantification score to a security analyst.
Owner:QATAR FOUND FOR EDUCATION SCI & COMMUNITY DEV +1

User based threat response recommendations

Techniques described herein can generate customized, user-based security response recommendations for users of security system(s), such as for security analysts tasked with performing responses to computing security threats. A user-based response recommendation engine can generate the user-based security response recommendations based on incident data associated with security incidents and based on historical user response data. Furthermore, user role inference techniques can optionally be used in conjunction with the user-based response recommendation engine.
Owner:CISCO TECHNOLOGY INC

Inference of user roles based on behavioral clustering

Techniques described herein can generate customized, user-based security response recommendations for users of security system(s), such as for security analysts tasked with performing responses to computing security threats. A user-based response recommendation engine can generate the user-based security response recommendations based on incident data associated with security incidents and based on historical user response data. Furthermore, user role inference techniques can optionally be used in conjunction with the user-based response recommendation engine.
Owner:CISCO TECHNOLOGY INC

Inference of user roles based on behavioral clustering

Techniques described herein can generate customized, user-based security response recommendations for users of security system(s), such as for security analysts tasked with performing responses to computing security threats. A user-based response recommendation engine can generate the user-based security response recommendations based on incident data associated with security incidents and based on historical user response data. Furthermore, user role inference techniques can optionally be used in conjunction with the user-based response recommendation engine.
Owner:CISCO TECHNOLOGY INC

Protection for electronic communications

A method includes acquiring a first video stream including a first instance of a user from a first video meeting, determining that the user is not modified, and creating a reference record for the user that includes a face biometric reference signature. The method includes acquiring subsequent video streams and updating the reference record to include an additional reference signature for the user. The method includes, during a current video stream, detecting a face biometric event if a current face biometric signature for the user deviates from the face biometric reference signature and detecting an additional event if a current additional signature for the user deviates from the additional reference signature. The method includes providing a response to a security analyst based on whether the face biometric event and the additional event were detected, wherein the response is selected from a table that maps responses to events.
Owner:GETREAL SECURITY INC

Network security Text-to-KQL query generation method and system based on mode screening and semantic verification and storage medium

The invention provides a network security Text-to-KQL query generation method and system based on pattern screening and semantic verification and a storage medium. The method comprises the steps that S1, data input and task definition are carried out; a user natural language query Q and a whole database mode S are received, Q is a natural language retrieval / analysis intention of the user, and S represents a set of all tables and fields in the system; s2, performing mode optimization based on a mixed attention model; s3, candidate KQL generation based on few-sample self-adaption is carried out; and S4, performing KQL verification and selection based on execution of signature and reasoning. The method has the beneficial effects that the problem of how to accurately and efficiently convert the natural language into the KQL query statement is solved, the technical threshold of security analysts in the data query process is reduced, the data query and analysis efficiency is improved, and the network security protection capability and response speed are enhanced.
Owner:HARBIN INSTITUTE OF TECHNOLOGY (SHENZHEN) (INSTITUTE OF SCIENCE AND TECHNOLOGY INNOVATION HARBIN INSTITUTE OF TECHNOLOGY SHENZHEN)

Real-time automated extraction of campaign CTI from threat reports

PendingUS20260149741A1Semantic analysisComputer security arrangementsSecurity operations centerEngineering
A pipeline has been created that leverages artificial intelligence and machine learning to efficiently extract information from CTI reports obtained from various sources and yielding information that assists security analysts / threat teams (e.g., security operations centers (SoCs)) and improving the quality of CTI. The “CTI analysis pipeline” employs generative artificial intelligence (“genAI”) to summarize a collection of CTI threat reports and extract threat-related information including TTPs from the CTI reports. Relationships among the threat reports are determined based on the extracted threat-related information and encoded in a graph structure. Graph embeddings based on the relationships encoded in the graph structure and semantic embeddings from the report summaries are combined and the combined embeddings are clustered. The resulting clusters and trained clustering model can be used in various ways to improve CTI, such as determining malicious campaigns, augmenting existing campaign information, and detecting new IOCs and TTPs for existing campaigns and new campaigns.
Owner:PALO ALTO NETWORKS INC

Protection for electronic communications

PCT designated stageWO2026147764A1Electronic communicationEngineering
A method includes acquiring a first video stream including a first instance of a user from a first video meeting, determining that the user is not modified, and creating a reference record for the user that includes a face biometric reference signature. The method includes acquiring subsequent video streams and updating the reference record to include an additional reference signature for the user. The method includes, during a current video stream, detecting a face biometric event if a current face biometric signature for the user deviates from the face biometric reference signature and detecting an additional event if a current additional signature for the user deviates from the additional reference signature. The method includes providing a response to a security analyst based on whether the face biometric event and the additional event were detected, wherein the response is selected from a table that maps responses to events.
Owner:GETREAL SECURITY INC

APT attack behavior-oriented portrait quality evaluation method and system, and terminal equipment

The invention provides an APT (Advanced Persistent Threat) attack behavior-oriented portrait quality evaluation method and system and terminal equipment. The method comprises the following steps: constructing an evaluation index system covering multiple dimensions; setting a weight grade for each evaluation index of the evaluation index system; collecting evaluation index data of the to-be-evaluated portrait, and performing standardization processing on the collected data to obtain a standardization score; processing the missing index data, and performing compensation by adopting preset penalty score filling or weight recalculation according to the missing type; and calculating a comprehensive evaluation score based on the weight and the standardized score of each index, calculating a weight coverage rate of an effective coverage degree of quantitative index data, calculating an observation score reflecting effective observation index performance, and obtaining a quantitative evaluation result of the APT attack behavior portrait quality based on a calculation result. According to the method, comprehensive quantitative evaluation can be carried out on the APT attack behavior portrait, and security analysts are assisted in improving the credibility and practicability of a portrait system in attack traceability and defense decision making.
Owner:CSG EHV POWER TRANSMISSION

A method and system for detecting injection vulnerabilities in Java Web applications

This invention discloses a method and system for detecting injection vulnerabilities in Java Web applications, relating to the field of computer network security. To improve the security of Java Web applications, it performs injection vulnerability detection, providing vulnerability detection services for security analysts and testers in the SDLC (Software as a Service) phase. This invention models the generation principle of injection vulnerabilities and constructs a prior knowledge rule base to mark class methods. A breadth-first taint analysis algorithm is used to analyze the Source method, constructing a local function call graph and storing taint propagation information during function calls in this graph. Branch path pruning is performed based on the taint propagation information in the graph, and finally, the injection vulnerability call chain is output by depth-first traversal of the local function call graph. This method significantly improves the efficiency of vulnerability analysis and the vulnerability detection rate.
Owner:INSTITUTE OF INFORMATION ENGINEERING CHINESE ACADEMY OF SCIENCES

Network security text-to-kql query generation method and system based on pattern screening and semantic verification, and storage medium

The application provides a network security Text-to-KQL query generation method and system based on pattern screening and semantic verification and a storage medium, and the method comprises the following steps: S1, data input and task definition; receiving a user natural language query Q and a whole database pattern S, wherein Q is a user natural language retrieval / analysis intention, and S represents a set of all tables and fields in the system; S2, pattern optimization based on a hybrid attention model; S3, candidate KQL generation based on few-shot adaptation; and S4, KQL verification and selection based on execution signature and reasoning. The application has the beneficial effects that the application solves the problem of how to accurately and efficiently convert a natural language into a KQL query statement, reduces the technical threshold of a security analyst in a data query process, improves the efficiency of data query and analysis, and enhances the ability and response speed of network security protection.
Owner:HARBIN INSTITUTE OF TECHNOLOGY (SHENZHEN) (INSTITUTE OF SCIENCE AND TECHNOLOGY INNOVATION HARBIN INSTITUTE OF TECHNOLOGY SHENZHEN)

Malicious code advanced identification method based on static analysis and semantic generation

The invention discloses a malicious code advanced identification method based on static analysis and semantic generation, which comprises the following steps of: firstly, performing disassembling and P-Code intermediate representation conversion on a binary file by utilizing a disassembling tool, and extracting a function level control flow diagram and basic block characteristics thereof; then coding the control flow graph based on a graph convolutional network, and learning embedded representation of nodes and a global graph; a node attention mechanism and a memory enhanced sequence generation model are introduced, and graph structure information is decoded into a function name sequence in a natural language form; and finally, malicious intention judgment is performed on the generated semantic content in combination with an expert knowledge base and a large language model, and identification and classification of malicious codes are completed. According to the method, the adaptability to obfuscated codes and cross-architecture binary files is remarkably improved, the interpretability of model output is enhanced, and visual and reliable decision support is provided for security analysts.
Owner:SOUTHEAST UNIV

Vehicle threat prediction method and device based on time and space, and medium

The invention relates to a time and space-based vehicle threat prediction method and device, and a medium. The method comprises the steps of collecting vehicle characteristics of a vehicle at each moment; forming a vehicle feature matrix corresponding to the grid at the moment by the vehicle features of all vehicles in the same geographic position grid at each moment; calculating spatio-temporal characteristics corresponding to each vehicle at each moment; collecting characteristics of each piece of network security information appearing at each moment; calculating the similarity between every two of the spatio-temporal features of all vehicles and the features of all network security information at each moment; and judging the relevance between the vehicle and the network security information based on the similarity between the spatial-temporal characteristics of the vehicle and the characteristics of the network security information. According to the invention, a more formalized and universal scheme for automatically sensing threats is constructed, which is helpful for security analysts to quickly respond and process.
Owner:XIAMEN YAXON ZHILLAN TECHNOLOGY CO LTD

Data processing method and device, storage medium and electronic equipment

The embodiment of the invention discloses a data processing method and device, a storage medium and electronic equipment, and the method comprises the steps: obtaining a target search processing language code in a rule operation and maintenance scene from a code analysis input interface, determining a target logic operator corresponding to the target search processing language code and hierarchical relationship information corresponding to the target logic operator, determining a conditional clause corresponding to the target logic operator, and generating a code structure display graph based on the hierarchical relationship information, the target logic operator and the conditional clause, and displaying the code structure display diagram on the code analysis input interface. Therefore, the code structure display graph is generated through the hierarchical relationship information, the target logic operator and the condition clause, so that the target search processing language code is converted into a structure form which is convenient to understand and can be refined, the structure form is displayed in the code structure display graph, and safety analysts are helped to quickly understand the target search processing language code.
Owner:BEIJING QIHOOD TECHNOLOGY CO LTD