Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

469 results about "Security analytics" patented technology

A Definition of Security Analytics. Security analytics is the process of using data collection, aggregation, and analysis tools for security monitoring and threat detection. Depending on the types of tools installed, security analytics solutions can incorporate large and diverse data sets into their detection algorithms.

Security Methods and Systems for Multi-Agent Generative AI Applications

A system and method for securing inter-process communications (IPCs) between generative AI and external tool servers, including intercepting IPCs having a requested operation, performing a security analysis on the IPCs for security threats, performing a permission validation for permissions for the requested operation of each IPC, and either approving or blocking the requested operation of each IPC based on the security analysis and the permission validation.
Owner:MADISETTI VIJAY

Cybersecurity threat detection and mitigation classification system

In some implementations, a cybersecurity threat detection and mitigation system is provided. The system refines an artificial intelligence (AI) model with a corpus of historical data that represents security events that occurred, queries that were submitted by security analysts in response to the security events, and actions that were performed for mitigating the security events. Telemetry data that corresponds to behavior and performance of a computer network is collected and provided to the AI model. Based on the telemetry data, the AI model predicts a potential security threat to the computer network and performs an assessment of risk to the computer network. When the assessment of risk to the computer network indicates that the potential security threat is an actual security threat, a security alert that corresponds to the actual security threat is triggered. Other embodiments are described and claimed.
Owner:ARCTIC WOLF NETWORKS INC

Security event association analysis and question and answer method and system and medium

The invention provides a security event association analysis and question answering method and system and a medium, and the method comprises the following steps: context-aware query completion: receiving an original query input by a user, obtaining a historical record of a current dialogue, and forming a context enhanced query according to the original query and the historical record of the current dialogue; dynamic task identification: outputting a prediction task model according to the context enhancement query in combination with a dynamic task identification strategy; multi-dimensional retrieval: performing multi-dimensional retrieval on the prediction task model to obtain a final knowledge context packet; and knowledge-driven response generation: generating a knowledge-driven response based on the knowledge context packet, and outputting a final security analysis report after the generated content passes verification. According to the method, efficient, accurate and explainable intelligent association analysis of the multi-source heterogeneous security data is realized by constructing a multi-dimensional knowledge base, designing a dynamic task recognition mechanism and realizing context-aware query completion.
Owner:HARBIN INSTITUTE OF TECHNOLOGY (SHENZHEN) (INSTITUTE OF SCIENCE AND TECHNOLOGY INNOVATION HARBIN INSTITUTE OF TECHNOLOGY SHENZHEN)

Large language model generation content security test system and method in black box scene

The invention discloses a big language model generation content security test system and method in a black box scene. The system comprises a jailbreak prompt word library module used for storing jailbreak prompt words for performing security test on a big language model; the violation question and answer pair module is used for storing violation question and answer pairs covering different types; the response acquisition module is used for obtaining a data request packet according to query content formed by the jailbreak prompt word and the query request; the security analysis module is used for calculating the similarity between response data corresponding to the query request and an expected violation answer, taking the similarity as a security score, and inputting the security score into the adaptive optimization module; and the adaptive optimization module is used for optimizing the jailbreak prompt words output by the jailbreak prompt word bank module by using a genetic algorithm according to the security score output by the security analysis module. According to the method and the device, the security of the large language model generation content can be effectively tested.
Owner:CHINA ELECTRONICS TECH CYBER SECURITY CO LTD +1

Brand-focused security administrator engine in an item listing system

PendingUS20250390894A1Mathematical modelsMachine learningSecurity metricEngineering
Methods, systems, and computer storage media for providing brand-focused security administration in an item listing system are described. Using a brand-focused machine learning model, the brand-focused security administrator engine supports generating different comprehensive reports and analytics on brand-related security metrics, including brand compliance rates, infringement incidents, enforcement actions taken, and overall item listing system integrity. The brand-focused security administrator engine also supports visualizing the brand-focused security analytics results data in a manner that enhances usability and decision-making by presenting complex brand-focused security analytics results data in a clear, actionable format. In operation, brand-focused security data is accessed. The brand-focused security data is analyzed using a brand-focused machine learning model that is trained based on a multi-dimensional authenticity analysis dataset. Brand-focused security analytics results data is generated. The brand-focused security analytics results data is communicated to cause display of one or more visualizations based on the brand-focused security analytics results data.
Owner:EBAY INC

Warehouse-level vulnerability detection method and device based on large model function semantic abstract

The invention belongs to the technical field of software security, and particularly discloses a warehouse-level vulnerability detection method and device based on a large model function semantic abstract. The method comprises the following steps: generating a vulnerability detection abstract syntax tree according to a to-be-detected source code; generating an assembly prompt word according to the complete source code of the node function in the unprocessed state and the target semantic abstract, and analyzing the node function in the unprocessed state according to the assembly prompt word by calling the target large model; and determining a vulnerability detection result of the to-be-detected source code according to the initial function semantic abstract and the structured function semantic abstract. Through the above mode, the vulnerability detection abstract syntax tree is generated by using the program structure modeling strategy and the full function call graph is constructed, and then the semantic abstract of the structured function is determined by using the semantic understanding capability of the target large model, that is, deep security analysis and vulnerability mining are performed from the local function to the global context. Therefore, the accuracy and comprehensiveness of warehouse-level vulnerability detection can be effectively improved.
Owner:武汉金银湖实验室 +1

Anomaly detection based on ensemble machine learning model

A security platform employs a variety techniques and mechanisms to detect security related anomalies and threats in a computer network environment. The security platform is “big data” driven and employs machine learning to perform security analytics. The security platform performs user / entity behavioral analytics (UEBA) to detect the security related anomalies and threats, regardless of whether such anomalies / threats were previously known. The security platform can include both real-time and batch paths / modes for detecting anomalies and threats. By visually presenting analytical results scored with risk ratings and supporting evidence, the security platform enables network security administrators to respond to a detected anomaly or threat, and to take action promptly.
Owner:CISCO TECHNOLOGY INC

Unknown exploit detection using attack traffic analysis and real-time attack event streaming

Techniques for unknown exploit detection using attack traffic analysis and real-time attack event streaming are disclosed. In some embodiments, a system / process / computer program product for exploit detection using attack traffic analysis and real-time attack event streaming includes receiving a stream that includes a plurality of attack events from a security platform at a cloud security service; generating a cluster of attack events from the stream; and tagging the cluster with an unknown attack pattern for further automated security analysis at the cloud security service, wherein the tagged unknown attack pattern cluster does not match a preexisting signature for a known attack pattern.
Owner:PALO ALTO NETWORKS INC

Distribution network construction air-space integrated safety monitoring method based on unmanned aerial vehicle

The invention discloses an air-space integrated safety monitoring method for distribution network construction based on an unmanned aerial vehicle, and the method comprises the following steps: A, constructing an air-space integrated cooperative monitoring network, and collecting the multi-source data of a distribution network construction region through the air-space integrated cooperative monitoring network; c, constructing a construction safety analysis model; the construction safety analysis model comprises a data acquisition and preprocessing module, a multi-source data fusion analysis module, a risk diagnosis and evaluation module, an intelligent prediction and early warning module, an early warning decision and disposal module and a visualization and feedback module; and D, based on the trained construction safety analysis model, collecting multi-source data by using an air-space integrated cooperative monitoring network, and carrying out online monitoring, early warning and disposal on the construction safety of the distribution network in combination with a meteorological database. Unmanned aerial vehicle near-earth monitoring and satellite remote sensing data can be fused, the distribution network construction process is effectively monitored, and potential safety hazards are reduced.
Owner:STATE GRID HENAN ELECTRIC POWER CO HUIXIAN CITY POWER SUPPLY CO

Public multi-mode cloud network resource software security enhancement method based on neural symbol fusion reasoning

The invention relates to a public multi-mode cloud network resource software security enhancement method based on neural symbol fusion reasoning, which comprises the following steps: an intermediate representation generation stage: generating and optimizing an intermediate representation of a program through a fine-tuned large language model, and establishing semantic mapping from a source code to a structured logic representation; in the symbol language conversion stage, the intermediate representation generated by the large language model is converted into a domain-specific language fact set which can be recognized in the symbol logic reasoning stage, and formal and logic expression of program semantics is achieved; and a symbol logic reasoning stage: matching the fact set with the rule base through a symbol logic reasoning engine, performing detection and verification according to the safety rule, generating a structured report, and feeding back a result for optimization. The method is suitable for security enhancement of various core software systems in a public cloud network multi-modal network environment, high-precision security analysis is carried out on cross-modal and cross-subsystem fragmented codes in a compiling-free environment, and verifiable technical support is provided for public cloud network security control.
Owner:PEKING UNIV

Risk assessment method, system and equipment for hydrogen storage system of thermal power plant and storage medium

The invention belongs to the technical field of thermal power plant safety analysis, and relates to a risk assessment method, system and device for a hydrogen storage system of a thermal power plant and a storage medium. Comprising the following steps: collecting operation data of the hydrogen storage system in real time, and preprocessing the data; based on the preprocessed data, utilizing a trained Bayesian LSTM model to predict the hydrogen leakage probability; if the hydrogen leakage probability exceeds a preset threshold value, CFD is combined with the preprocessed data to simulate a diffusion behavior after hydrogen leakage, and the severity of a leakage event is calculated based on a simulation result; and inputting the hydrogen leakage probability and the severity of the leakage event into a Bayesian network model, calculating a risk value, and triggering a grading early warning mechanism according to the risk value. According to the method, the sensitivity and accuracy of risk identification are improved, the scientificity of early warning decision making is enhanced, and intelligent guarantee is provided for safe operation of the hydrogen storage system of the thermal power plant.
Owner:NORTHWEST ELECTRIC POWER DESIGN INST OF CHINA POWER ENG CONSULTING GRP

Chemical safety production safety intelligent analysis system based on large language model

The invention relates to the technical field of chemical safety intelligent analysis, and discloses a chemical safety production safety intelligent analysis system based on a large language model, and the system comprises a semantic data construction module which is used for obtaining multi-source data and building a standardized database, a semantic anchor point library and a causal fragment set; the mechanism constraint modeling module is used for generating a mechanism constraint library and mapping the mechanism constraint library with the device unit; the semantic compiling constraint module is used for compiling the natural language intention into a formalized constraint set; the interlocking generation matching module is used for generating a semantic interlocking table and an action list; the check amplitude limiting decision module is used for determining a reserved action list, an amplitude limiting parameter and an execution sequence; the simulation verification and evaluation module is used for carrying out full-track simulation and outputting a feasibility result; and the deviation revision backfilling module is used for comparing the actual working condition with the simulation track and generating a revision proposal. According to the method, self-adaptive closed-loop optimization of semantic knowledge unified modeling and safety analysis in the chemical safety production process is realized.
Owner:ZHICHUANG KONAN (HANGZHOU) TECH CO LTD

Audit data security management and control system based on big data

The invention discloses an auditing data security management and control system based on big data, and relates to the field of data management and control, and the system comprises a distributed crawler which collects auditing logs, operation records and network traffic in real time. And the stream batch integrated engine performs metadata alignment and timestamp synchronization on heterogeneous data to generate a unified audit event stream. The intelligent desensitization module carries out gradient desensitization on the sensitive fields and constructs reversible blood relationship mapping. According to the hierarchical storage, data are stored in an encrypted memory pool, an SSD and a cold standby cluster according to data sensitivity and access frequency, and consistent hash load balancing is achieved. Multi-modal safety monitoring analyzes data in real time through a three-level assembly line. And the hierarchical response module writes a permission chain according to the risk trigger action and the key audit event hash value, and constructs a tamper-proof evidence chain. The method has the advantages that the data security, privacy protection and efficient emergency response are ensured through intelligent desensitization, hierarchical storage and security analysis of the audit data, and the non-tampering property of the data is ensured by utilizing the block chain technology.
Owner:COLLEGE OF MOBILE TELECOMM CHONGQING UNIV OF POSTS & TELECOMM

Security sensing method and system for GPU (Graphic Processing Unit) cluster

The invention relates to the technical field of network security awareness, in particular to a security awareness method and system for a GPU cluster, and the method comprises the steps: collecting multi-source security situation data, and providing basic information for subsequent security analysis; by constructing and updating a cluster security situation map in real time, information timeliness is updated and ensured in real time, and powerful support is provided for risk assessment; a dynamic risk assessment model is utilized to calculate vertex and edge scores, high-risk vertexes and key risk conduction paths are identified, and a basis is provided for resource isolation and scheduling; the targeted instruction is generated according to the security risk score and the preset security policy library, different security risks are effectively handled, and safe and stable operation of the cluster is guaranteed; by converting the instruction into a specific control command and distributing and executing the specific control command, effective implementation of security measures is ensured, and the cluster security protection capability is improved; by setting a finite-state machine monitoring instruction execution state, a recovery mechanism is automatically triggered, and continuous and safe operation of the cluster is guaranteed.
Owner:中科云达(北京)科技有限公司

Source network load storage integrated n-1 scene voltage safety analysis method

The invention relates to the technical field of power system safety analysis, in particular to a source-grid-load-storage integrated n-1 scene voltage safety analysis method, which comprises the following steps of: acquiring and preprocessing n-1 scene data; constructing a static voltage safety analysis model based on the gradient boosting regression tree; constructing a dynamic voltage safety analysis model based on a long short-term memory network; analyzing safety collaboration of the static voltage and the dynamic voltage; and verifying and optimizing the static voltage safety analysis model and the dynamic voltage safety analysis model. According to the method, the static voltage stability margin and the dynamic response characteristic are fused, so that the comprehensive risk identification accuracy is improved; a gradient boosting regression tree and a long-short-term memory network are adopted to capture nonlinear characteristics, and the voltage prediction error of an n-1 scene is remarkably reduced; characteristics and weights are customized for different source network load storage integrated project types such as industrial and incremental power distribution networks, and the pertinence and engineering practicability of analysis are improved.
Owner:XUCHANG POWER SUPPLY COMPANY OF STATE GRID HENAN ELECTRIC POWER

Role-based access control recommendation systems

A method for role-based access control recommendation includes obtaining one or more security logs from a security analytics platform. The method includes determining access rights to the one or more security logs for one or more users of the security analytics platform. The determining includes generating one or more clusters of security logs based on the one or more security logs. The determining includes providing, to a user of the security analytics platform, a recommendation for a first data access group for the security analytics platform based on a first cluster of the one or more clusters. The determining includes, responsive to input from the user of the security analytics platform, generating the first data access group for the security analytics platform based on the first cluster of the one or more clusters.
Owner:GOOGLE LLC

Inspection method of nuclear power safety analysis report and applicable system and readable medium thereof

The invention provides a nuclear power safety analysis report examination method and an applicable system and a readable medium thereof, and relates to the technical field of nuclear power. The review method comprises the following steps: converting each design file into document fragment data through a knowledge maintenance agent, and storing the document fragment data into a knowledge base; converting the nuclear power safety analysis report into a plurality of to-be-examined text blocks through a document analysis agent; extracting at least one technical expression statement and a corresponding retrieval problem and a matched knowledge fragment from each to-be-examined text block through a retrieval composite agent; performing consistency judgment on each technical expression statement, and a retrieval problem and a matched knowledge fragment corresponding to the technical expression statement through a technical review agent to obtain initial review data; and obtaining a final examination decision agent and a historical examination database, and generating corresponding final examination data through the final examination decision agent according to the historical examination database and the initial examination data.
Owner:SHANGHAI NUCLEAR ENGINEERING RESEARCH & DESIGN INSTITUTE CO LTD

Old people home safety decision service system fused with multi-mode perception data

The invention relates to the technical field of sensing data processing, and discloses an old people home safety decision service system fusing multi-mode sensing data, which comprises a data interaction analysis unit, a data change analysis unit, a data calculation unit, a safety analysis unit and a safety decision unit. The hidden association of the multi-modal indexes is accurately captured, the early degradation of the collaboration level can be perceived through the graph condensation degree and the graph equilibrium value, the collaboration degradation track can be used for analyzing the collaboration state, and the finally generated safety decision instruction can perform early warning in advance. According to the scheme, single-mode threshold dependence is broken through, hidden dangers hidden in data correlation evolution are recognized in advance, and the lagging of home safety decision of old people is solved.
Owner:XIAMEN GUANGYI BOXUI TECH CO LTD

Power transmission line channel point cloud modeling method and system

The invention belongs to the technical field of power transmission line modeling, and provides a power transmission line channel point cloud modeling method and system, and the technical scheme is that based on standardized point cloud data, global statistical features are extracted, channel scene categories are automatically judged, and adaptive feature weight vectors are generated according to the judged scene categories; performing weighted calculation on the similarity by using the feature weight vector, and performing superbody clustering segmentation on the standardized point cloud data to obtain an optimized superbody set formed by a plurality of superbodies with similar internal features; based on multi-dimensional feature statistics and context rules, screening the optimized superbody set, and rejecting small non-ground interference superbodies to obtain a ground candidate superbody set; and performing identification, merging and curved surface fitting on the ground candidate superbody set to generate a continuous power transmission line channel ground model. High-precision identification of ground points is realized, and a high-quality ground reference can be provided for safety analysis of a power transmission channel.
Owner:STATE GRID INTELLIGENCE TECHNOLOGY CO LTD

Safety management method and system based on artificial intelligence and big data

The invention relates to the technical field of safety monitoring artificial intelligence, and discloses a safety management method and system based on artificial intelligence and big data. The method comprises the steps that multi-modal real-time monitoring data is collected through a distributed sensor array, and a standardized sequence is generated after preprocessing; the system accesses a historical security event library, adaptively divides risk category clusters by using an unsupervised clustering algorithm, and extracts key risk features and influence domains for each cluster. On the basis, a plurality of special self-adaptive security analysis engines are configured to perform parallel analysis on real-time data to generate a plurality of security analysis feature maps. And carrying out weighted fusion and enhancement on the feature maps through a feature fusion network to obtain a unified security situation feature vector, and finally outputting a security level and a management and control instruction through a decision model. According to the method, autonomous identification, dynamic evaluation and accurate response of complex risks are realized, and the intelligent level of safety management and the decision accuracy are improved.
Owner:SHENYANG UNIV

Honeypot interaction response generation method based on large language model

A honeypot interaction response generation method based on a large language model comprises the steps that an attacker initiates a malicious request, a firewall carries out screening based on a white list, and traffic matched with the white list is forwarded to an actual application server through a honeypot system; for the traffic not in the white list, redirecting the traffic to a honeypot system; a honeypot interaction response system is deployed in the honeypot system and comprises an embedding module, a coding module and a response decoding module, so that induction response is automatically generated and sent to an attacker, and meanwhile alarm information is generated and sent to safety analysts. The method comprises the following steps: firstly, converting input data into a vector form by using an embedding module, extracting overall characteristics of a request by using a coding module, and finally, generating an induced response by using a response decoding module. According to the method, the advantages of a large language model in the aspects of semantic comprehension, context modeling and generation capability are fully utilized, and accurate perception of attack behaviors and automatic generation of response contents are realized.
Owner:NANJING COLLEGE OF INFORMATION TECH

Software component analysis system based on artificial intelligence

The invention relates to the technical field of artificial intelligence, in particular to a software component analysis system based on artificial intelligence, which comprises a data acquisition and preprocessing unit, an AI-driven component identification and analysis unit, a risk detection and evaluation unit, a knowledge base and dynamic updating unit and a result visualization and disposal suggestion unit. According to the method, through a collaborative mechanism of multi-modal semantic fingerprint generation, cross-language component matching and dynamic and static feature dual verification, the bottleneck that traditional software component analysis is insufficient in recognition precision of high-confusion, cross-language and secondary packaging components is effectively broken through, and precise recognition and analysis of the components and key attributes thereof are achieved; therefore, a more reliable technical support which better meets actual business requirements is provided for software component security analysis.
Owner:SHANGHAI RUNXUNDA DIGITAL TECH CO LTD

Power protection measurement and control terminal information security protection method, system, equipment and medium

The invention discloses an electric power protection measurement and control terminal information security protection method, system and device and a medium, and the method comprises the steps: building an environment fingerprint database through collecting the physical quantity of a power grid, carrying out the threat level evaluation, and adjusting a security strategy; based on the environment fingerprint database and the threat level evaluation result, classifying the transmission data, deploying quantum key distribution nodes in the transformer substation, and providing differentiated secure transmission for different types of transmission data; and in combination with the environment fingerprint database and the differentiated secure transmission data, executing cognitive security analysis, establishing an anomaly detection model, and obtaining threat traceability visual positioning. According to the method, the dynamic environment fingerprint database is constructed by collecting multi-dimensional physical quantities and is bound with the digital certificate to form a dual authentication mechanism, so that the defect that a traditional scheme depends on static cryptography is overcome, real-time perception and adaptive response to a complex and changeable electromagnetic environment are realized, and the security of the system is improved. And the environmental adaptability and the safety protection capability of the system are obviously improved.
Owner:GUIZHOU POWER GRID CO LTD

Buildless dependency fetching

Some embodiments construct a set of build dependencies for a program without a full set of build instructions. The build dependency set is constructed without piggy-backing on a build process that would produce an executable version of the program. Representations of the program's structure, such as expression types, call targets, symbol tables, abstract syntax trees, and other internal compiler data structures, are emitted to persistent non-volatile storage instead of being used only as intermediate steps for executable code generation. Security analysis can then utilize the program representations. Licensing analysis can also utilize the dependency set to identify program components and their storage locations.
Owner:MICROSOFT TECHNOLOGY LICENSING LLC

Forklift safety analysis system fusing multi-modal data

The invention relates to the technical field of forklift safety analysis, in particular to a forklift safety analysis system fusing multi-modal data, which comprises a multi-modal data acquisition module, an environment-level safety analysis module, a vehicle-level safety analysis module, a behavior-level safety analysis module, a dynamic decision engine, a safety intervention module and a model optimization module. By collecting multi-modal data, constructing a dynamic environment risk model, a forklift comprehensive performance model and a sub-scene safety evaluation model and fusing multi-dimensional analysis results to generate a multi-level instruction, early warning and active control are achieved, and robustness is improved through self-optimization. The problems that a traditional technology depends on single data, a fixed threshold value fails, and closed-loop intervention is lacked are solved, and the forklift operation safety and efficiency can be comprehensively improved.
Owner:SPECIAL EQUIP SAFETY SUPERVISION INSPECTION INST OF JIANGSU PROVINCE

Dam hidden danger classification data set construction method based on semi-automatic active learning

The invention relates to the technical field of data processing and artificial intelligence, in particular to a dam hidden danger classification data set construction method based on semi-automatic active learning, and the method comprises the steps: calling a dam safety analysis component to generate a multi-dimensional analysis abstract for unlabeled multi-modal data; screening out records with content contradictions and information sparseness, and labeling the records by experts; dynamically updating the instruction set according to the expert label and carrying out generative cross-modal expansion; organizing all the marked hidden danger records and the expanded hidden danger records into a structured data unit containing positive, negative and difficult samples, and constructing a domain knowledge index through sample comparison; and continuously accumulating the structured data units in the closed loop step, and finally constructing a dam hidden danger classification data set. According to the method, the domain knowledge index constructed in the circulation serves as a new round of information retrieval tool, continuous accumulation of knowledge is achieved, and the efficiency and quality of data set construction are improved.
Owner:NANJING HYDRAULIC RES INST

Network security analysis method and system based on system log audit analysis

The invention provides a network security analysis method and system based on system log auditing analysis, and belongs to the technical field of network security. Behavior chain knitting processing is executed on a streaming log sequence by capturing the streaming log sequence generated by network nodes of a power monitoring system in real time, and the network security is obtained. Associating continuous operation record entries of the same operation main body to form a dynamic behavior chain, performing mode matching on the dynamic behavior chain based on a preset security rule base, identifying candidate behavior fragments, performing reverse traceability analysis on the candidate behavior fragments, constructing a risk diffusion diagram, and performing risk analysis on the risk diffusion diagram. And finally, generating a security analysis report containing a risk source node, a diffusion path and an affected resource list, and pushing the security analysis report to a security management and control center, so that the real-time performance, accuracy and comprehensiveness of network security analysis of the power monitoring system can be effectively improved, and safe and stable operation of the power system is ensured.
Owner:XINYUAN NETWORK TECH CO LTD

Centralized security analysis and management of source code in network environments

Disclosed embodiments relate to systems and methods for centrally analyzing and managing source code. Techniques include identifying, at a centralized resource in a network environment, a first source code; identifying the first source code as a candidate for an execution of an access control action; identifying, at the centralized resource, a security risk indication for the first source code, the security risk indication being based on permissions associated with a functionality of the first source code; performing, based on the security risk indication, at least one of: developing a least privilege set of permissions for the source code, or modifying the least privilege set of permissions.
Owner:CYBER ARK SOFTWARE LTD

Identity privacy protection system and method for safe sharing of power data

PendingCN121561950AData processing applicationsDigital data protectionChosen-plaintext attackAttack
The invention discloses an identity privacy protection system and method oriented to power data security sharing, which combine single-factor combination authentication and identity traceability and utilize the transparency and tamper resistance of a block chain. Comprising an electric power key generation center, an electric power cloud service provider, an electric power data owner, an electric power data user and a block chain, user identity privacy is ensured, safe identity verification is supported, identity traceability is achieved under necessary conditions, and meanwhile safe distribution of keys is achieved. In addition, services and resources are isolated by using groups, so that the flexibility and the expandability of the services and the resources are enhanced. Security analysis and experimental evaluation prove that the method can effectively resist selected plaintext attacks, and meanwhile, high efficiency and practicability are kept.
Owner:STATE GRID HENAN INFORMATION & TELECOMM CO

Open source software component security analysis method, device, equipment and medium

The invention relates to an open source software component safety analysis method, device and equipment and a medium, and is applied to the technical field of software safety analysis. The method comprises the steps that open source information of open source software and an open source component of the open source software are acquired; performing file feature analysis on the open source software based on the open source information and the open source component to generate a multi-link component dependency relationship; generating a component list based on the multi-link component dependency relationship and the open source component; obtaining existing vulnerability information of the open source software; based on the multi-link dependency relationship, the component list and the existing vulnerability information, constructing a component security analysis library; and performing component security analysis on target software based on the component security analysis library. The method has the effect of timely and accurately determining the safety of the open source software.
Owner:BILING (ZHUHAI HENGQIN) TECHNOLOGY CO LTD