Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

50 results about "Security analyst" patented technology

Dynamic delivery of vehicle event data

An improved system and method of selectively transmitting asset data from one or more sensors associated with the vehicle to a backend server, which is configured to analyze the asset data and, if necessary for further analysis of the asset data (e.g., to determine whether a safety event has occurred) and / or to provide actionable data for review by a safety analyst, requests further asset data from a vehicle device.
Owner:SAMSARA INC

Cybersecurity threat detection and mitigation classification system

In some implementations, a cybersecurity threat detection and mitigation system is provided. The system refines an artificial intelligence (AI) model with a corpus of historical data that represents security events that occurred, queries that were submitted by security analysts in response to the security events, and actions that were performed for mitigating the security events. Telemetry data that corresponds to behavior and performance of a computer network is collected and provided to the AI model. Based on the telemetry data, the AI model predicts a potential security threat to the computer network and performs an assessment of risk to the computer network. When the assessment of risk to the computer network indicates that the potential security threat is an actual security threat, a security alert that corresponds to the actual security threat is triggered. Other embodiments are described and claimed.
Owner:ARCTIC WOLF NETWORKS INC

Data security event real-time monitoring method and system

The invention relates to the field of internet attack detection, in particular to a data security event real-time monitoring method and system, and the method comprises data collection, multi-modal fusion, threat detection, causal reasoning, dynamic response and feedback optimization. Compared with the traditional security analysis which depends on isolated data dimension or simple rule association, is difficult to capture a cross-data-source complex attack mode, and is faced with the limitations of low calculation efficiency, slow link traceability, storage access bottleneck and the like in mass data association analysis, the scheme integrates multi-source heterogeneous data into a dynamic association network through graph structure modeling, so that the security analysis efficiency is improved. Hidden association and behavior patterns among users, equipment and IPs are deeply mined by utilizing a GNN framework, the suspicious degree among entities can be accurately quantified, and hidden attack chains can be identified; and meanwhile, a hybrid storage architecture and a query optimization technology are adopted, so that a security analyst can backtrack a complex attack path in a second level while breaking through the bottleneck of large-scale graph data access performance, and the threat hunting efficiency and the high-level attack traceability are remarkably improved.
Owner:JINAN DINGXIA DIGITAL TECHNOLOGY CO LTD

User based threat response recommendations

Techniques described herein can generate customized, user-based security response recommendations for users of security system(s), such as for security analysts tasked with performing responses to computing security threats. A user-based response recommendation engine can generate the user-based security response recommendations based on incident data associated with security incidents and based on historical user response data. Furthermore, user role inference techniques can optionally be used in conjunction with the user-based response recommendation engine.
Owner:CISCO TECHNOLOGY INC

Network threat report attack knowledge graph automatic construction method and system based on large language model, storage medium and program product

The invention relates to a network threat report attack knowledge graph automatic construction method and system based on a large language model, a storage medium and a program product, and the method comprises the steps: carrying out the iterative processing of extracted entities and relationships through a clustering method based on the large language model, and generating an initial attack knowledge graph; according to the invention, aggregation processing is carried out on a plurality of technology example threat reports belonging to the same attack technology through an attack technology graph template generation mechanism, a standardized attack technology standardized template library is established, and automatic attack technology tagging of new threat reports is realized by adopting an attack technology alignment method based on Word2Vec and WordNet, so that the automatic attack technology tagging of the new threat reports is realized. And a complete attack technology knowledge graph is constructed, so that a security analyst can quickly understand an attack path and a key threat point, and the automation degree and the accuracy of threat intelligence analysis are remarkably improved.
Owner:STATE GRID SHANGHAI MUNICIPAL ELECTRIC POWER CO +1

Artificial intelligence cyber security analyst

An analyzer module forms a hypothesis on what are a possible set of cyber threats that could include the identified abnormal behavior and / or suspicious activity with AI models trained with machine learning on possible cyber threats. The Analyzer analyzes a collection of system data, including metric data, to support or refute each of the possible cyber threat hypotheses that could include the identified abnormal behavior and / or suspicious activity data with the AI models. A formatting and ranking module outputs supported possible cyber threat hypotheses into a formalized report that is presented in 1) printable report, 2) presented digitally on a user interface, or 3) both.
Owner:DARKTRACE HLDG LTD

System and method for combining intelligent alarm study and judgment with safe operation system

ActiveCN120415918ASecuring communicationSecurity information and event managementData mining
The invention discloses an intelligent alarm research and judgment and safety operation system combined system and method, and the system comprises an alarm classification device which is used for receiving alarm information and original logs from a safety information and event management system, and classifying alarms into a class A, a class B and a class C; the small model research and judgment module is used for processing the A-type alarms and calculating a false alarm probability through local endogenous information matching and a naive Bayes algorithm; the large model research and judgment module is used for processing the B-type alarms and generating a research and judgment result based on the extracted alarm vulnerability information and a preset question template; the manual research and judgment module is used for processing the C-type alarms and alarms which cannot pass through small model research and judgment or large model research and judgment; and the alarm memory is used for storing research and judgment results and mark information of all alarms. According to the method, the workload of a security analyst is reduced, the alarm average response time is prolonged, and the number of alarms processed manually is reduced on the premise that the missing report rate is not obviously increased.
Owner:SHANDONG XINGWEI JIUZHOU SECURITY TECH CO LTD

Security patch variant positioning method based on two-dimensional feature design

The invention belongs to the technical field of open source software supply chain security, and particularly relates to a security patch variant positioning method based on two-dimensional feature design. By designing the two-dimensional features and applying the rule model, comprehensive, accurate and automatic positioning of the security patch variants in the specified open source software code warehouse is realized. The method comprises the following specific steps: data preprocessing: extracting basic information in a submission record and carrying out normalization processing; feature generation: designing and calculating similar features and characterization features of submission record pairs; and variant prediction: predicting the extracted features by applying a random forest model, and judging whether the submitted record is the security patch variant according to a prediction score. According to the method, by widely mining similar features and characterization features between patch variants and combining with a rule-based model, the comprehensiveness, accuracy and automation degree of patch variant positioning are improved, and an effective patch variant positioning tool is provided for software security analysts.
Owner:FUDAN UNIVERSITY

Inference of user roles based on behavioral clustering

Techniques described herein can generate customized, user-based security response recommendations for users of security system(s), such as for security analysts tasked with performing responses to computing security threats. A user-based response recommendation engine can generate the user-based security response recommendations based on incident data associated with security incidents and based on historical user response data. Furthermore, user role inference techniques can optionally be used in conjunction with the user-based response recommendation engine.
Owner:CISCO TECHNOLOGY INC

Security framework matrix visualizations for notable events

Techniques are described for generating visualizations of security framework information (such as, e.g., MITRE ATT&CK® information) displayed in connection with notable events detected by a data intake and query system. Data intake and query systems, SIEM systems, and other applications often provide user interfaces that display detected occurrences of incidents, sometimes referred to as “notable events,” within users' information technology (IT) environments. A data intake and query system is described herein that is capable of identifying notable events, assigning tactic and technique information to notable events (and optionally to associated risk objects), and causing display of tactic and technique visualizations which are intuitive and customizable, provide ready access to relevant documentation, and follow a format with which security analysts are familiar.
Owner:CISCO TECHNOLOGY INC

Holographic flow monitoring method and system based on AI and BI

The invention discloses a holographic flow monitoring method and system based on AI and BI, and relates to the technical field of network security monitoring. The method comprises the steps of flow collection and data processing, realization of multi-dimensional feature extraction, multi-model detection and dynamic decision by an AI engine, realization of trend, region and situation analysis by a BI engine, realization of anomaly detection based on a behavior baseline, and realization of AI detection result optimization and triggering of BI cross-dimension analysis by an adaptive weight algorithm. The holographic flow monitoring system is constructed through big data driving and fusion of an AI big model, millisecond-level real-time analysis of a security data flow is realized, immediate response of emergency events such as 0day attacks and the like is met, static rule limitation is broken through, the detection accuracy of unknown threats and APT attacks is improved, an AI analysis result and BI visualization capability are fused, and the system has a good application prospect. Multi-dimensional insight of the traffic situation is realized; low-latency interactive query is provided, and ad hoc data exploration of security analysts is supported.
Owner:SHENZHEN Y& D ELECTRONICS CO LTD

Inference of user roles based on behavioral clustering

PCT designated stageWO2025174504A1Securing communicationEvent dataEngineering
Techniques described herein can generate customized, user-based security response recommendations for users of security system(s), such as for security analysts tasked with performing responses to computing security threats. A user-based response recommendation engine can generate the user-based security response recommendations based on incident data associated with security incidents and based on historical user response data. Furthermore, user role inference techniques can optionally be used in conjunction with the user-based response recommendation engine.
Owner:CISCO TECHNOLOGY INC

Quantifying satisfaction of security features of cloud software systems

A method of quantifying the satisfaction of security requirements is provided via characterizing a security feature; matching the security feature to a security metric; computing a quantification score that indicates the exploitability of a system to which the security feature is applied; and outputting the quantification score to a security analyst.
Owner:QATAR FOUND FOR EDUCATION SCI & COMMUNITY DEV +1

User based threat response recommendations

Techniques described herein can generate customized, user-based security response recommendations for users of security system(s), such as for security analysts tasked with performing responses to computing security threats. A user-based response recommendation engine can generate the user-based security response recommendations based on incident data associated with security incidents and based on historical user response data. Furthermore, user role inference techniques can optionally be used in conjunction with the user-based response recommendation engine.
Owner:CISCO TECHNOLOGY INC

Inference of user roles based on behavioral clustering

Techniques described herein can generate customized, user-based security response recommendations for users of security system(s), such as for security analysts tasked with performing responses to computing security threats. A user-based response recommendation engine can generate the user-based security response recommendations based on incident data associated with security incidents and based on historical user response data. Furthermore, user role inference techniques can optionally be used in conjunction with the user-based response recommendation engine.
Owner:CISCO TECHNOLOGY INC

Inference of user roles based on behavioral clustering

Techniques described herein can generate customized, user-based security response recommendations for users of security system(s), such as for security analysts tasked with performing responses to computing security threats. A user-based response recommendation engine can generate the user-based security response recommendations based on incident data associated with security incidents and based on historical user response data. Furthermore, user role inference techniques can optionally be used in conjunction with the user-based response recommendation engine.
Owner:CISCO TECHNOLOGY INC

Intelligent adaptive network security monitoring system and use method thereof

The invention relates to an intelligent adaptive network security monitoring system and a use method thereof, and aims to realize real-time monitoring of network traffic, accurate identification of abnormal behaviors and effective response through a deep learning technology. The system extracts key features by comprehensively analyzing various data sources such as network flow data, user behavior logs and system security logs, and performs learning and pattern recognition on the features by using advanced deep learning models such as a convolutional neural network and a recurrent neural network. On the basis, the system can automatically identify abnormal behaviors which do not conform to the normal behavior mode, and measures such as network isolation and access limitation are rapidly taken through a predefined response strategy module, so that the influence of potential threats is reduced. In addition, the system provides a visual instrument board and a detailed security report, and helps a security analyst to better understand the network security state and make a decision. According to the system and the using method thereof, the accuracy and the response speed of network security protection are improved, and the dynamic change of a network environment can be adapted through continuous learning and self-adaptive adjustment, so that more powerful and flexible guarantee is provided for the security of a network space.
Owner:张韶晴

System and method for surfacing cyber-security threats with a self-learning recommendation engine

Techniques for performing cyber-security alert analysis and prioritization according to machine learning employing a predictive model to implement a self-learning feedback loop. The system implements a method generating the predictive model associated with alert classifications and / or actions which automatically generated, or manually selected by cyber-security analysts. The predictive model is used to determine a priority for display to the cyber-security analyst and to obtain the input of the cyber-security analyst to improve the predictive model. Thereby the method implements a self-learning feedback loop to receive cyber-security alerts and mitigate the cyberthreats represented in the cybersecurity alerts.
Owner:GOOGLE LLC

Protection for electronic communications

A method includes acquiring a first video stream including a first instance of a user from a first video meeting, determining that the user is not modified, and creating a reference record for the user that includes a face biometric reference signature. The method includes acquiring subsequent video streams and updating the reference record to include an additional reference signature for the user. The method includes, during a current video stream, detecting a face biometric event if a current face biometric signature for the user deviates from the face biometric reference signature and detecting an additional event if a current additional signature for the user deviates from the additional reference signature. The method includes providing a response to a security analyst based on whether the face biometric event and the additional event were detected, wherein the response is selected from a table that maps responses to events.
Owner:GETREAL SECURITY INC

A system and method combining intelligent alarm research and judgment with a safe operation system

ActiveCN120415918BSecuring communicationSecurity information and event managementAlarm analysis
The present invention discloses a system and method combining intelligent alarm analysis and judgment with a security operation system. The system includes an alarm classification device for receiving alarm information and original logs from a security information and event management system and classifying alarms into Class A, Class B, and Class C. A small model analysis and judgment module is used to process Class A alarms and calculate the probability of false alarms through local endogenous intelligence matching and a naive Bayesian algorithm. A large model analysis and judgment module is used to process Class B alarms and generate analysis and judgment results based on extracted alarm vulnerability information and preset question templates. A manual analysis and judgment module is used to process Class C alarms and alarms that cannot be analyzed by the small model or the large model. An alarm storage device is used to store the analysis and judgment results and tag information of all alarms. The present invention reduces the workload of security analysts, improves the average alarm response time, and reduces the number of manually processed alarms without significantly increasing the false alarm rate.
Owner:SHANDONG XINGWEI JIUZHOU SECURITY TECH CO LTD

Using an artificial intelligence (AI) algorithm to identify patterns in ai algorithm weights to create newly trained ai algorithms without using traditional ai algorithm training techniques

In a first embodiment, an initial set of base AI inputs are used to define a base set of AI output data. Weights of the AI algorithm are changed in to identify how the changes to the weights affect the base AI output data. This information is used to create a new set of weights for the AI algorithm. In a second embodiment, the base set of AI output data can be used to determine how compromised weights of an AI algorithm affect bias of the AI algorithm. This information can then be displayed to a security analyst to help determine how the AI algorithm has been compromised. In a third embodiment, a weight pattern AI algorithm is trained using a plurality of training sets. The weight sets generated by training the AI algorithm are used to train a weight pattern AI algorithm that can produce new weight sets.
Owner:MICRO FOCUS LLC

A method for generating a honeypot interaction response based on a large language model

ActiveCN120750578BLinguistic modelAttack
A method for generating a honeypot interaction response based on a large language model, an attacker initiates a malicious request, a firewall will be based on a whitelist screening, for the traffic matching the whitelist, through the honeypot system to the actual application server; for the traffic not in the whitelist, then redirect to the honeypot system; The honeypot system is deployed with a honeypot interaction response system, which includes an embedding module, a coding module and a response decoding module, so as to automatically generate an induced response and send it to the attacker, while generating an alarm information and sending it to the security analyst. The present application first uses the embedding module to convert the input data into vector form, and uses the coding module to extract the overall characteristics of the request, and finally uses the response decoding module to generate the induced response. The present application makes full use of the advantages of large language model in semantic understanding, context modeling and generation ability, realizes the accurate perception of attack behavior and the automatic generation of response content.
Owner:NANJING COLLEGE OF INFORMATION TECH

A knowledge graph-based threat analysis method and system for the Internet of Vehicles and a medium

This invention relates to a knowledge graph-based method, system, and medium for vehicular network (V2X) threat analysis. The method includes: U1. collecting data information of V2X entity objects and V2X threat intelligence; U2. based on the V2X threat intelligence data, extracting feature information of the V2X threat intelligence using a hierarchical clustering algorithm based on expected cross-entropy to obtain feature matrix data information of the V2X threat intelligence, and using a Spearman rank correlation coefficient-based cross-validation algorithm to characterize the correlation between entity objects and the feature matrix of the V2X threat intelligence to obtain data information on the correlation between V2X entity objects and threat intelligence. This invention not only solves the problem of not being able to comprehensively cover the identification of threats in all dimensions of V2X, but also provides a comprehensive and intuitive display of V2X threat intelligence from various angles, facilitating automotive security analysts to flexibly analyze the V2X security situation.
Owner:GUANGZHOU HAIPERTE TECH CO LTD

Hidden patch positioning method based on single-class learning

The invention belongs to the technical field of open source software supply chain security, and particularly relates to a hidden patch positioning method based on single-class learning. The method comprises the following steps: generating a security indicator from an original security patch message as a basis for subsequent single-classification model learning; through positive sample variant generation and difficult negative sample generation, learning is performed on the data set to promote security features; training a patch message encoder by using the designed loss function to learn security patch features; a patch message is converted into a vector through an encoder, and the similarity between the vector and a known security patch vector is calculated, so that a hidden security patch is positioned. Through the single-class learning model, the hidden patch positioning accuracy is effectively improved, and a powerful hidden patch identification tool is provided for software security analysts.
Owner:FUDAN UNIVERSITY

Network security Text-to-KQL query generation method and system based on mode screening and semantic verification and storage medium

The invention provides a network security Text-to-KQL query generation method and system based on pattern screening and semantic verification and a storage medium. The method comprises the steps that S1, data input and task definition are carried out; a user natural language query Q and a whole database mode S are received, Q is a natural language retrieval / analysis intention of the user, and S represents a set of all tables and fields in the system; s2, performing mode optimization based on a mixed attention model; s3, candidate KQL generation based on few-sample self-adaption is carried out; and S4, performing KQL verification and selection based on execution of signature and reasoning. The method has the beneficial effects that the problem of how to accurately and efficiently convert the natural language into the KQL query statement is solved, the technical threshold of security analysts in the data query process is reduced, the data query and analysis efficiency is improved, and the network security protection capability and response speed are enhanced.
Owner:HARBIN INSTITUTE OF TECHNOLOGY (SHENZHEN) (INSTITUTE OF SCIENCE AND TECHNOLOGY INNOVATION HARBIN INSTITUTE OF TECHNOLOGY SHENZHEN)

A method, system, storage medium and program product for automatically constructing a network threat report attack knowledge graph based on a large language model

The present invention relates to a method, system, storage medium and program product for automatically constructing a network threat report attack knowledge graph based on a large language model. The method generates an initial attack knowledge graph by iteratively processing the extracted entities and relationships through a clustering method based on a large language model. At the same time, the present invention aggregates multiple technical example threat reports belonging to the same attack technology through an attack technology graph template generation mechanism, establishes a standardized template library for standardized attack technologies, and adopts an attack technology alignment method based on Word2Vec and WordNet to realize automatic attack technology labeling of new threat reports, construct a complete attack technology knowledge graph, facilitate security analysts to quickly understand attack paths and key threat points, and significantly improve the automation and accuracy of threat intelligence analysis.
Owner:STATE GRID SHANGHAI MUNICIPAL ELECTRIC POWER CO +1

Over-authority vulnerability black box detection method based on cross-request data dependency tracking mechanism

PendingCN120602180ASecuring communicationWeb siteData dependency graph
The invention discloses an unauthorized vulnerability black box detection method based on a cross-request data dependency tracking mechanism. The method is used for identifying identity verification and authorization security problems with vulnerabilities in network applications. According to the method, a cross-request data dependency tracking mechanism is introduced to deduce an operation dependency relationship between pages, analyze feedback content and judge whether unauthorized reading or modifying operation exists or not, so that the detection of unauthorized vulnerabilities is realized. The method comprises the following specific steps: preprocessing: preparing an initial address of a target website and registering accounts of a common user and an attacker; constructing a cross-request data dependency graph, and establishing a dependency relationship among different operation requests; and vulnerability detection: tracking an attacker request through the cross-request data dependency graph so as to judge whether a vulnerability exists or not. According to the method for detecting the unauthorized vulnerability through the black box, the recall rate, the accuracy rate and the automation degree of unauthorized vulnerability detection are improved, and an effective unauthorized vulnerability detection tool is provided for software security analysts.
Owner:FUDAN UNIVERSITY

Concept drift detection method and system based on feature analysis

PendingCN120541482ABiological modelsInterquartile rangeLabeled data
The invention provides a concept drift detection method and system based on feature analysis, and belongs to the field of network security, and the method comprises the steps: S1, enabling an autoencoder to be enhanced through comparative learning, enabling an input sample to be mapped to a low-dimensional potential space from an original high-dimensional space, and employing a method based on a quartile distance to detect a drift sample; s2, identifying key features causing drifting of the drifting sample through a feature selection algorithm; and S3, generating a new synthetic sample through interpolation between the drift sample and the nearest neighbor sample by adopting a synthetic minority class oversampling method so as to balance the class distribution of the samples. According to the method, sample-level concept drift detection is achieved, dependence on a large amount of labeled data is reduced, an interpretation method based on feature selection is provided, key features causing drift can be recognized and associated with semantically related features, and interpretable drift evidences are provided for security analysts.
Owner:INSTITUTE OF INFORMATION ENGINEERING CHINESE ACADEMY OF SCIENCES

Real-time automated extraction of campaign CTI from threat reports

PendingUS20260149741A1Semantic analysisComputer security arrangementsSecurity operations centerEngineering
A pipeline has been created that leverages artificial intelligence and machine learning to efficiently extract information from CTI reports obtained from various sources and yielding information that assists security analysts / threat teams (e.g., security operations centers (SoCs)) and improving the quality of CTI. The “CTI analysis pipeline” employs generative artificial intelligence (“genAI”) to summarize a collection of CTI threat reports and extract threat-related information including TTPs from the CTI reports. Relationships among the threat reports are determined based on the extracted threat-related information and encoded in a graph structure. Graph embeddings based on the relationships encoded in the graph structure and semantic embeddings from the report summaries are combined and the combined embeddings are clustered. The resulting clusters and trained clustering model can be used in various ways to improve CTI, such as determining malicious campaigns, augmenting existing campaign information, and detecting new IOCs and TTPs for existing campaigns and new campaigns.
Owner:PALO ALTO NETWORKS INC

Protection for electronic communications

PCT designated stageWO2026147764A1Electronic communicationEngineering
A method includes acquiring a first video stream including a first instance of a user from a first video meeting, determining that the user is not modified, and creating a reference record for the user that includes a face biometric reference signature. The method includes acquiring subsequent video streams and updating the reference record to include an additional reference signature for the user. The method includes, during a current video stream, detecting a face biometric event if a current face biometric signature for the user deviates from the face biometric reference signature and detecting an additional event if a current additional signature for the user deviates from the additional reference signature. The method includes providing a response to a security analyst based on whether the face biometric event and the additional event were detected, wherein the response is selected from a table that maps responses to events.
Owner:GETREAL SECURITY INC