Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

32 results about "Security analyst" patented technology

Cybersecurity threat detection and mitigation classification system

In some implementations, a cybersecurity threat detection and mitigation system is provided. The system refines an artificial intelligence (AI) model with a corpus of historical data that represents security events that occurred, queries that were submitted by security analysts in response to the security events, and actions that were performed for mitigating the security events. Telemetry data that corresponds to behavior and performance of a computer network is collected and provided to the AI model. Based on the telemetry data, the AI model predicts a potential security threat to the computer network and performs an assessment of risk to the computer network. When the assessment of risk to the computer network indicates that the potential security threat is an actual security threat, a security alert that corresponds to the actual security threat is triggered. Other embodiments are described and claimed.
Owner:ARCTIC WOLF NETWORKS INC

Security framework matrix visualizations for notable events

Techniques are described for generating visualizations of security framework information (such as, e.g., MITRE ATT&CK® information) displayed in connection with notable events detected by a data intake and query system. Data intake and query systems, SIEM systems, and other applications often provide user interfaces that display detected occurrences of incidents, sometimes referred to as “notable events,” within users' information technology (IT) environments. A data intake and query system is described herein that is capable of identifying notable events, assigning tactic and technique information to notable events (and optionally to associated risk objects), and causing display of tactic and technique visualizations which are intuitive and customizable, provide ready access to relevant documentation, and follow a format with which security analysts are familiar.
Owner:CISCO TECHNOLOGY INC

Holographic flow monitoring method and system based on AI and BI

The invention discloses a holographic flow monitoring method and system based on AI and BI, and relates to the technical field of network security monitoring. The method comprises the steps of flow collection and data processing, realization of multi-dimensional feature extraction, multi-model detection and dynamic decision by an AI engine, realization of trend, region and situation analysis by a BI engine, realization of anomaly detection based on a behavior baseline, and realization of AI detection result optimization and triggering of BI cross-dimension analysis by an adaptive weight algorithm. The holographic flow monitoring system is constructed through big data driving and fusion of an AI big model, millisecond-level real-time analysis of a security data flow is realized, immediate response of emergency events such as 0day attacks and the like is met, static rule limitation is broken through, the detection accuracy of unknown threats and APT attacks is improved, an AI analysis result and BI visualization capability are fused, and the system has a good application prospect. Multi-dimensional insight of the traffic situation is realized; low-latency interactive query is provided, and ad hoc data exploration of security analysts is supported.
Owner:SHENZHEN Y& D ELECTRONICS CO LTD

Quantifying satisfaction of security features of cloud software systems

A method of quantifying the satisfaction of security requirements is provided via characterizing a security feature; matching the security feature to a security metric; computing a quantification score that indicates the exploitability of a system to which the security feature is applied; and outputting the quantification score to a security analyst.
Owner:QATAR FOUND FOR EDUCATION SCI & COMMUNITY DEV +1

User based threat response recommendations

Techniques described herein can generate customized, user-based security response recommendations for users of security system(s), such as for security analysts tasked with performing responses to computing security threats. A user-based response recommendation engine can generate the user-based security response recommendations based on incident data associated with security incidents and based on historical user response data. Furthermore, user role inference techniques can optionally be used in conjunction with the user-based response recommendation engine.
Owner:CISCO TECHNOLOGY INC

Inference of user roles based on behavioral clustering

Techniques described herein can generate customized, user-based security response recommendations for users of security system(s), such as for security analysts tasked with performing responses to computing security threats. A user-based response recommendation engine can generate the user-based security response recommendations based on incident data associated with security incidents and based on historical user response data. Furthermore, user role inference techniques can optionally be used in conjunction with the user-based response recommendation engine.
Owner:CISCO TECHNOLOGY INC

Inference of user roles based on behavioral clustering

Techniques described herein can generate customized, user-based security response recommendations for users of security system(s), such as for security analysts tasked with performing responses to computing security threats. A user-based response recommendation engine can generate the user-based security response recommendations based on incident data associated with security incidents and based on historical user response data. Furthermore, user role inference techniques can optionally be used in conjunction with the user-based response recommendation engine.
Owner:CISCO TECHNOLOGY INC

Intelligent adaptive network security monitoring system and use method thereof

The invention relates to an intelligent adaptive network security monitoring system and a use method thereof, and aims to realize real-time monitoring of network traffic, accurate identification of abnormal behaviors and effective response through a deep learning technology. The system extracts key features by comprehensively analyzing various data sources such as network flow data, user behavior logs and system security logs, and performs learning and pattern recognition on the features by using advanced deep learning models such as a convolutional neural network and a recurrent neural network. On the basis, the system can automatically identify abnormal behaviors which do not conform to the normal behavior mode, and measures such as network isolation and access limitation are rapidly taken through a predefined response strategy module, so that the influence of potential threats is reduced. In addition, the system provides a visual instrument board and a detailed security report, and helps a security analyst to better understand the network security state and make a decision. According to the system and the using method thereof, the accuracy and the response speed of network security protection are improved, and the dynamic change of a network environment can be adapted through continuous learning and self-adaptive adjustment, so that more powerful and flexible guarantee is provided for the security of a network space.
Owner:张韶晴

Protection for electronic communications

A method includes acquiring a first video stream including a first instance of a user from a first video meeting, determining that the user is not modified, and creating a reference record for the user that includes a face biometric reference signature. The method includes acquiring subsequent video streams and updating the reference record to include an additional reference signature for the user. The method includes, during a current video stream, detecting a face biometric event if a current face biometric signature for the user deviates from the face biometric reference signature and detecting an additional event if a current additional signature for the user deviates from the additional reference signature. The method includes providing a response to a security analyst based on whether the face biometric event and the additional event were detected, wherein the response is selected from a table that maps responses to events.
Owner:GETREAL SECURITY INC

A system and method combining intelligent alarm research and judgment with a safe operation system

ActiveCN120415918BSecuring communicationSecurity information and event managementAlarm analysis
The present invention discloses a system and method combining intelligent alarm analysis and judgment with a security operation system. The system includes an alarm classification device for receiving alarm information and original logs from a security information and event management system and classifying alarms into Class A, Class B, and Class C. A small model analysis and judgment module is used to process Class A alarms and calculate the probability of false alarms through local endogenous intelligence matching and a naive Bayesian algorithm. A large model analysis and judgment module is used to process Class B alarms and generate analysis and judgment results based on extracted alarm vulnerability information and preset question templates. A manual analysis and judgment module is used to process Class C alarms and alarms that cannot be analyzed by the small model or the large model. An alarm storage device is used to store the analysis and judgment results and tag information of all alarms. The present invention reduces the workload of security analysts, improves the average alarm response time, and reduces the number of manually processed alarms without significantly increasing the false alarm rate.
Owner:SHANDONG XINGWEI JIUZHOU SECURITY TECH CO LTD

Using an artificial intelligence (AI) algorithm to identify patterns in ai algorithm weights to create newly trained ai algorithms without using traditional ai algorithm training techniques

In a first embodiment, an initial set of base AI inputs are used to define a base set of AI output data. Weights of the AI algorithm are changed in to identify how the changes to the weights affect the base AI output data. This information is used to create a new set of weights for the AI algorithm. In a second embodiment, the base set of AI output data can be used to determine how compromised weights of an AI algorithm affect bias of the AI algorithm. This information can then be displayed to a security analyst to help determine how the AI algorithm has been compromised. In a third embodiment, a weight pattern AI algorithm is trained using a plurality of training sets. The weight sets generated by training the AI algorithm are used to train a weight pattern AI algorithm that can produce new weight sets.
Owner:MICRO FOCUS LLC

A method for generating a honeypot interaction response based on a large language model

ActiveCN120750578BLinguistic modelAttack
A method for generating a honeypot interaction response based on a large language model, an attacker initiates a malicious request, a firewall will be based on a whitelist screening, for the traffic matching the whitelist, through the honeypot system to the actual application server; for the traffic not in the whitelist, then redirect to the honeypot system; The honeypot system is deployed with a honeypot interaction response system, which includes an embedding module, a coding module and a response decoding module, so as to automatically generate an induced response and send it to the attacker, while generating an alarm information and sending it to the security analyst. The present application first uses the embedding module to convert the input data into vector form, and uses the coding module to extract the overall characteristics of the request, and finally uses the response decoding module to generate the induced response. The present application makes full use of the advantages of large language model in semantic understanding, context modeling and generation ability, realizes the accurate perception of attack behavior and the automatic generation of response content.
Owner:NANJING COLLEGE OF INFORMATION TECH

A knowledge graph-based threat analysis method and system for the Internet of Vehicles and a medium

This invention relates to a knowledge graph-based method, system, and medium for vehicular network (V2X) threat analysis. The method includes: U1. collecting data information of V2X entity objects and V2X threat intelligence; U2. based on the V2X threat intelligence data, extracting feature information of the V2X threat intelligence using a hierarchical clustering algorithm based on expected cross-entropy to obtain feature matrix data information of the V2X threat intelligence, and using a Spearman rank correlation coefficient-based cross-validation algorithm to characterize the correlation between entity objects and the feature matrix of the V2X threat intelligence to obtain data information on the correlation between V2X entity objects and threat intelligence. This invention not only solves the problem of not being able to comprehensively cover the identification of threats in all dimensions of V2X, but also provides a comprehensive and intuitive display of V2X threat intelligence from various angles, facilitating automotive security analysts to flexibly analyze the V2X security situation.
Owner:GUANGZHOU HAIPERTE TECH CO LTD

Network security Text-to-KQL query generation method and system based on mode screening and semantic verification and storage medium

The invention provides a network security Text-to-KQL query generation method and system based on pattern screening and semantic verification and a storage medium. The method comprises the steps that S1, data input and task definition are carried out; a user natural language query Q and a whole database mode S are received, Q is a natural language retrieval / analysis intention of the user, and S represents a set of all tables and fields in the system; s2, performing mode optimization based on a mixed attention model; s3, candidate KQL generation based on few-sample self-adaption is carried out; and S4, performing KQL verification and selection based on execution of signature and reasoning. The method has the beneficial effects that the problem of how to accurately and efficiently convert the natural language into the KQL query statement is solved, the technical threshold of security analysts in the data query process is reduced, the data query and analysis efficiency is improved, and the network security protection capability and response speed are enhanced.
Owner:HARBIN INSTITUTE OF TECHNOLOGY (SHENZHEN) (INSTITUTE OF SCIENCE AND TECHNOLOGY INNOVATION HARBIN INSTITUTE OF TECHNOLOGY SHENZHEN)

A method, system, storage medium and program product for automatically constructing a network threat report attack knowledge graph based on a large language model

The present invention relates to a method, system, storage medium and program product for automatically constructing a network threat report attack knowledge graph based on a large language model. The method generates an initial attack knowledge graph by iteratively processing the extracted entities and relationships through a clustering method based on a large language model. At the same time, the present invention aggregates multiple technical example threat reports belonging to the same attack technology through an attack technology graph template generation mechanism, establishes a standardized template library for standardized attack technologies, and adopts an attack technology alignment method based on Word2Vec and WordNet to realize automatic attack technology labeling of new threat reports, construct a complete attack technology knowledge graph, facilitate security analysts to quickly understand attack paths and key threat points, and significantly improve the automation and accuracy of threat intelligence analysis.
Owner:STATE GRID SHANGHAI MUNICIPAL ELECTRIC POWER CO +1

Real-time automated extraction of campaign CTI from threat reports

PendingUS20260149741A1Semantic analysisComputer security arrangementsSecurity operations centerEngineering
A pipeline has been created that leverages artificial intelligence and machine learning to efficiently extract information from CTI reports obtained from various sources and yielding information that assists security analysts / threat teams (e.g., security operations centers (SoCs)) and improving the quality of CTI. The “CTI analysis pipeline” employs generative artificial intelligence (“genAI”) to summarize a collection of CTI threat reports and extract threat-related information including TTPs from the CTI reports. Relationships among the threat reports are determined based on the extracted threat-related information and encoded in a graph structure. Graph embeddings based on the relationships encoded in the graph structure and semantic embeddings from the report summaries are combined and the combined embeddings are clustered. The resulting clusters and trained clustering model can be used in various ways to improve CTI, such as determining malicious campaigns, augmenting existing campaign information, and detecting new IOCs and TTPs for existing campaigns and new campaigns.
Owner:PALO ALTO NETWORKS INC

Protection for electronic communications

PCT designated stageWO2026147764A1Electronic communicationEngineering
A method includes acquiring a first video stream including a first instance of a user from a first video meeting, determining that the user is not modified, and creating a reference record for the user that includes a face biometric reference signature. The method includes acquiring subsequent video streams and updating the reference record to include an additional reference signature for the user. The method includes, during a current video stream, detecting a face biometric event if a current face biometric signature for the user deviates from the face biometric reference signature and detecting an additional event if a current additional signature for the user deviates from the additional reference signature. The method includes providing a response to a security analyst based on whether the face biometric event and the additional event were detected, wherein the response is selected from a table that maps responses to events.
Owner:GETREAL SECURITY INC

APT attack behavior-oriented portrait quality evaluation method and system, and terminal equipment

The invention provides an APT (Advanced Persistent Threat) attack behavior-oriented portrait quality evaluation method and system and terminal equipment. The method comprises the following steps: constructing an evaluation index system covering multiple dimensions; setting a weight grade for each evaluation index of the evaluation index system; collecting evaluation index data of the to-be-evaluated portrait, and performing standardization processing on the collected data to obtain a standardization score; processing the missing index data, and performing compensation by adopting preset penalty score filling or weight recalculation according to the missing type; and calculating a comprehensive evaluation score based on the weight and the standardized score of each index, calculating a weight coverage rate of an effective coverage degree of quantitative index data, calculating an observation score reflecting effective observation index performance, and obtaining a quantitative evaluation result of the APT attack behavior portrait quality based on a calculation result. According to the method, comprehensive quantitative evaluation can be carried out on the APT attack behavior portrait, and security analysts are assisted in improving the credibility and practicability of a portrait system in attack traceability and defense decision making.
Owner:CSG EHV POWER TRANSMISSION

APT attack path traceability method and device based on traceability graph

The invention discloses an APT attack path traceability method and device based on a traceability graph, and belongs to the technical field of computer network security. The method comprises the following steps: constructing a traceability graph G of a network to be analyzed; encoding semantic information of the interaction event into vectors, and encoding the vectors into attributes of the nodes at the two ends according to a time sequence to obtain semantic features xi of the nodes; calculating an intimacy matrix of the traceability graph G, and constructing a correlation sub-graph of each node according to the intimacy matrix; on the basis of the semantic feature xi, generating a depth representation zi of the node in combination with a correlation subgraph; and obtaining abnormal nodes and abnormal edges in the traceability graph G based on the semantic feature xi and the depth representation zi. According to the method, the attack path can be accurately reconstructed, and an accurate traceability basis is provided for security analysts.
Owner:INSTITUTE OF INFORMATION ENGINEERING CHINESE ACADEMY OF SCIENCES

A method and system for detecting injection vulnerabilities in Java Web applications

This invention discloses a method and system for detecting injection vulnerabilities in Java Web applications, relating to the field of computer network security. To improve the security of Java Web applications, it performs injection vulnerability detection, providing vulnerability detection services for security analysts and testers in the SDLC (Software as a Service) phase. This invention models the generation principle of injection vulnerabilities and constructs a prior knowledge rule base to mark class methods. A breadth-first taint analysis algorithm is used to analyze the Source method, constructing a local function call graph and storing taint propagation information during function calls in this graph. Branch path pruning is performed based on the taint propagation information in the graph, and finally, the injection vulnerability call chain is output by depth-first traversal of the local function call graph. This method significantly improves the efficiency of vulnerability analysis and the vulnerability detection rate.
Owner:INSTITUTE OF INFORMATION ENGINEERING CHINESE ACADEMY OF SCIENCES

Network security text-to-kql query generation method and system based on pattern screening and semantic verification, and storage medium

The application provides a network security Text-to-KQL query generation method and system based on pattern screening and semantic verification and a storage medium, and the method comprises the following steps: S1, data input and task definition; receiving a user natural language query Q and a whole database pattern S, wherein Q is a user natural language retrieval / analysis intention, and S represents a set of all tables and fields in the system; S2, pattern optimization based on a hybrid attention model; S3, candidate KQL generation based on few-shot adaptation; and S4, KQL verification and selection based on execution signature and reasoning. The application has the beneficial effects that the application solves the problem of how to accurately and efficiently convert a natural language into a KQL query statement, reduces the technical threshold of a security analyst in a data query process, improves the efficiency of data query and analysis, and enhances the ability and response speed of network security protection.
Owner:HARBIN INSTITUTE OF TECHNOLOGY (SHENZHEN) (INSTITUTE OF SCIENCE AND TECHNOLOGY INNOVATION HARBIN INSTITUTE OF TECHNOLOGY SHENZHEN)

System and Method for Surfacing Cyber-Security Threats with a Self-Learning Recommendation Engine

Techniques for performing cyber-security alert analysis and prioritization according to machine learning employing a predictive model to implement a self-learning feedback loop. The system implements a method generating the predictive model associated with alert classifications and / or actions which automatically generated, or manually selected by cyber-security analysts. The predictive model is used to determine a priority for display to the cyber-security analyst and to obtain the input of the cyber-security analyst to improve the predictive model. Thereby the method implements a self-learning feedback loop to receive cyber-security alerts and mitigate the cyberthreats represented in the cybersecurity alerts.
Owner:GOOGLE LLC

Data security detection method, device, equipment, medium and product

The invention provides a data security detection method and apparatus, a device, a medium and a product. The method comprises the steps of obtaining data, related to security detection, of a to-be-detected service system; a knowledge graph is constructed based on the data, the data are analyzed based on the knowledge graph, a security assessment result is obtained, and the knowledge graph is used for representing the association relationship between the data in the service system. Wherein the knowledge graph can intuitively display the relationship among the entities and help security analysts to quickly understand the structure and potential safety hazards of the to-be-detected business system, and the segmented data can be comprehensively analyzed through the knowledge graph. Therefore, the security risk can be identified and evaluated more effectively, the efficiency and accuracy of security detection are improved, a scientific basis is provided for security management, and the overall security protection capability is enhanced.
Owner:CHINA MOBILE FINANCIAL TECHNOLOGY CO LTD +1

Malicious code advanced identification method based on static analysis and semantic generation

The invention discloses a malicious code advanced identification method based on static analysis and semantic generation, which comprises the following steps of: firstly, performing disassembling and P-Code intermediate representation conversion on a binary file by utilizing a disassembling tool, and extracting a function level control flow diagram and basic block characteristics thereof; then coding the control flow graph based on a graph convolutional network, and learning embedded representation of nodes and a global graph; a node attention mechanism and a memory enhanced sequence generation model are introduced, and graph structure information is decoded into a function name sequence in a natural language form; and finally, malicious intention judgment is performed on the generated semantic content in combination with an expert knowledge base and a large language model, and identification and classification of malicious codes are completed. According to the method, the adaptability to obfuscated codes and cross-architecture binary files is remarkably improved, the interpretability of model output is enhanced, and visual and reliable decision support is provided for security analysts.
Owner:SOUTHEAST UNIV

Vehicle threat prediction method and device based on time and space, and medium

The invention relates to a time and space-based vehicle threat prediction method and device, and a medium. The method comprises the steps of collecting vehicle characteristics of a vehicle at each moment; forming a vehicle feature matrix corresponding to the grid at the moment by the vehicle features of all vehicles in the same geographic position grid at each moment; calculating spatio-temporal characteristics corresponding to each vehicle at each moment; collecting characteristics of each piece of network security information appearing at each moment; calculating the similarity between every two of the spatio-temporal features of all vehicles and the features of all network security information at each moment; and judging the relevance between the vehicle and the network security information based on the similarity between the spatial-temporal characteristics of the vehicle and the characteristics of the network security information. According to the invention, a more formalized and universal scheme for automatically sensing threats is constructed, which is helpful for security analysts to quickly respond and process.
Owner:XIAMEN YAXON ZHILLAN TECHNOLOGY CO LTD

Attack behavior modeling method and system based on correlation analysis

The invention discloses an attack behavior modeling method and system based on correlation analysis, and the method comprises the steps: obtaining and preprocessing multi-dimensional security data collected by each data collection port, carrying out the analysis of the preprocessed multi-dimensional security data, recognizing an attack behavior, and carrying out the analysis of the attack behavior. Mining association rules between the attack behaviors and determining attack features of the attack behaviors; analyzing the association rule, determining a numerical value of a preset evaluation index, and evaluating the value of the association rule based on the numerical value of the preset evaluation index to obtain an association rule value evaluation value; determining a high-value association rule based on the association rule value evaluation value, and determining an attack mode based on the high-value association rule and the attack characteristics; and constructing an attack behavior model based on the attack pattern, the association rule and the attack feature to identify a potential attack behavior. According to the method, network security threats can be found and dealt with in time, more comprehensive security intelligence can be provided for security analysts, and the security analysts are helped to better understand and deal with continuously changing network security threats.
Owner:HUANENG INFORMATION TECH CO LTD

A network attack investigation method and system based on enhanced traceability graph retrieval

The present invention provides a network attack investigation method and system based on enhanced traceability graph retrieval, comprising: collecting logs from multiple platforms and processing them into a unified format; constructing the processed logs into a traceability graph using a traceability graph construction algorithm; identifying and detecting activity communities in the traceability graph to reveal the associations between sensitive activities; generating a multi-level summary of system activities based on the traceability graph, covering community summaries, entity summaries, and relationship summary information; improving the accuracy of query responses and the efficiency of information extraction through GraphRAG technology, and providing attack investigation reports through an interactive query interface. The present invention can process logs collected by multiple platforms and different log collectors, more efficiently capture the full picture of complex attacks, provide security analysts with comprehensive and rapid attack investigation results, and provide support for network security forensic analysis.
Owner:WUHAN UNIV

Artificial intelligence cyber security analyst

An analyzer module forms a hypothesis on what are a possible set of cyber threats that could include the identified abnormal behavior and / or suspicious activity with AI models trained with machine learning on possible cyber threats. The Analyzer analyzes a collection of system data, including metric data, to support or refute each of the possible cyber threat hypotheses that could include the identified abnormal behavior and / or suspicious activity data with the AI models. A formatting and ranking module outputs supported possible cyber threat hypotheses into a formalized report that is presented in 1) printable report, 2) presented digitally on a user interface, or 3) both.
Owner:DARKTRACE HLDG LTD

Intelligent agent-oriented injection type vulnerability grey box detection method

The invention discloses an agent-oriented injection type vulnerability grey box detection method, which is used for detecting injection type vulnerabilities in an LLM-based agent. According to the method, efficient detection of injection type vulnerabilities is realized by introducing LLM to assist in generating natural language seed cue words with specific semantics, seed cue word scheduling driven by multi-dimensional feedback and semantic and parameter variators guided by Sink; the method comprises the following specific steps: firstly, generating a seed cue word with specific semantics in a natural language form by utilizing LLM (Logistics Language Model); secondly, evaluating the quality of the seed cues from the aspects of semantics and distance by utilizing multi-aspect feedback design, and preferentially considering the seed cues with higher quality; and finally, optimizing the seed cues and effectively triggering vulnerabilities by using semantics and parameter variators. According to the method, the injection type vulnerability in the intelligent agent of the LLM can be efficiently and automatically detected, and an effective detection tool for the injection type vulnerability of the intelligent agent is provided for software security analysts.
Owner:FUDAN UNIVERSITY

Data processing method and device, storage medium and electronic equipment

The embodiment of the invention discloses a data processing method and device, a storage medium and electronic equipment, and the method comprises the steps: obtaining a target search processing language code in a rule operation and maintenance scene from a code analysis input interface, determining a target logic operator corresponding to the target search processing language code and hierarchical relationship information corresponding to the target logic operator, determining a conditional clause corresponding to the target logic operator, and generating a code structure display graph based on the hierarchical relationship information, the target logic operator and the conditional clause, and displaying the code structure display diagram on the code analysis input interface. Therefore, the code structure display graph is generated through the hierarchical relationship information, the target logic operator and the condition clause, so that the target search processing language code is converted into a structure form which is convenient to understand and can be refined, the structure form is displayed in the code structure display graph, and safety analysts are helped to quickly understand the target search processing language code.
Owner:BEIJING QIHOOD TECHNOLOGY CO LTD