Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

59 results about "Security bug" patented technology

A security bug or security defect is a software bug that can be exploited to gain unauthorized access or privileges on a computer system. Security bugs need not be identified nor exploited to qualify as such.

A multi-level quantitative evaluation method for an electronic product information clearing, verifying and tracing credible closed loop system

PendingCN122346411ATechnology developmentAttack
The application discloses a kind of multi-level quantitative evaluation methods for electronic product information clearing, verification and traceable credible closed-loop system, comprising S100, evaluation framework establishment and test environment preparation step: S110, define evaluation model, the evaluation model includes clearing effect layer (L1), verification credible layer (L2), trace and authentication layer (L3), system behavior and security layer (L4) and performance and efficiency layer (L5).The application has the advantages that: from qualitative to quantitative: a large number of quantitative indicators such as KL divergence, bit recovery rate, throughput are introduced, and the evaluation results are objective, accurate and comparable.The method carries out deep security testing: not only test function, but also take the system itself as attack target, carry out penetration testing and process behavior monitoring, can find deeply hidden design defects and security vulnerabilities, which cannot be achieved by traditional function testing.At the same time, the method can guide technology development, and provide decision basis for procurement and supervision;And high automation and repeatability.
Owner:GUIZHOU UNIV

Software item dependency package management method

PendingCN122113107APlatform integrity maintainancePackage managementDatabase
The present disclosure relates to a software project dependency package management method, an electronic device and a computer readable storage medium. The software project dependency package management method comprises: detecting a security vulnerability of a dependency package in a software project based on a security vulnerability database and a dependency information file; generating a repair scheme according to the detection result; and updating the dependency information file to repair the security vulnerability according to the repair scheme, wherein the dependency information file comprises information for building a dependency tree of the software project.
Owner:UNIONPAY INT CO LTD

System for adaptive management of downstream technology elements

A system is provided for detecting and remediating computing system breaches using computing network traffic monitoring. In particular, the system may identify one or more technology elements within a network as well as relationships between computing systems associated with said elements to determine a network topology. Based on the network topology, the system may use historical network traffic data associated with the technology elements in the network to generate predicted entry points and lateral pathways of a security breach that may take place within particular computing systems. Then, based on the technology elements affected as well as entry points and path traversals of the breach, the system may generate and / or implement one or more remediation steps to address existing and / or future breaches. In this way, the system may provide an intelligent method of augmenting the security of a computing network.
Owner:BANK OF AMERICA CORP

A method for implementing island network vulnerability scanning based on Metasploit technology

ActiveCN117040815BComputer networkAttack
The application discloses a method for realizing island network vulnerability scanning based on Metasploit technology, which comprises the following steps: setting an intermediate machine with traffic relay function in the island network; connecting to the intermediate machine from an external network and building a Metasploit environment on the intermediate machine; penetrating the intermediate machine by using modular components and related attack technology in the Metasploit and obtaining the access right to the internal island network; scanning the host and running service in the island network by using the vulnerability scanning module in the Metasploit and transmitting the scanning result back to the intermediate machine. The method can discover and repair the possible security vulnerability in the island network, can comprehensively and deeply scan the island network, can flexibly scan the vulnerability and manage the security of the island network from the external network, and can transmit the scanning result back to the intermediate machine in real time to deal with the possible security threat in time.
Owner:YUNNAN POWER GRID CO LTD

Systems and methods for isolating programs in runtime and determining security vulnerabilities

A system is provided for isolating programs in runtime and determining security vulnerabilities. In particular, the system may comprise a protector AI engine that may analyze code of programs and applications at runtime within a virtualized or sandbox environment. The system may further provide obfuscated or decoy data to the code within the sandbox environment, where the obfuscated data may be quantum generated. The system may further comprise one or more patch AI bots that may be configured to generate patches or fixes to particular code blocks in real time upon detecting that the code blocks may be vulnerable. In this way, the system may detect and remedy security vulnerabilities in real time.
Owner:BANK OF AMERICA CORP

Method and apparatus for multi-peripheral register interaction protocol-aware firmware fuzzing

PendingCN122450835ACode coverageMultiple input
The application discloses a kind of multi-peripheral register interaction protocol perception's firmware fuzz testing method and equipment, it is related to firmware test technical field, method includes: in the process of carrying out fuzzy test to firmware, determine the multiple execution rounds of the firmware that triggers new code coverage;Multiple execution rounds each corresponding peripheral register access sequence is obtained;According to multiple peripheral register access sequence, frequent co-occurrence input stream sub-sequence is mined, wherein each input stream corresponds to a peripheral register;Select target sub-sequence in frequent co-occurrence input stream sub-sequence, simultaneously carry out variation to multiple input streams in target sub-sequence;Based on the input stream after variation, execute firmware, carry out fuzzy test to firmware.The application improves the code coverage of firmware fuzzy test while guaranteeing the efficiency of fuzzy test, and then increases the possibility of discovering more crashes and potential security vulnerabilities.
Owner:TECH & ENG CENT FOR SPACE UTILIZATION CHINESE ACAD OF SCI

Threat and risk detection from domain-level cloud content items

Systems and methods are disclosed herein for identifying security vulnerabilities within a domain. In an embodiment, a security application accesses logs of activity performed with respect to cloud content items within the domain and determines, using a plurality of machine learning models, a plurality of risk signals from the logs. The security application inputs the plurality of risk signals into a unified detection model and receives, as output from the unified detection model, risk classifications for a plurality of risks evident from the logs. The system determines, based on the risk classifications, at least one remedial action, and outputs a control signal instructing performance of the at least one remedial action.
Owner:MATERIAL SECURITY INC

A method for early warning of security vulnerability risks of an information system based on big data

ActiveCN118194290BOriginal dataThe Internet
The application discloses a kind of information system security vulnerability risk early warning method based on big data, comprising the following steps: step S1, the index library is established to enterprise internal various levels various types of information systems, network equipment, application software, and safety related data is collected;Step S2, integrate the security intelligence on Internet and third party vulnerability database, obtain the latest security vulnerability information, and carry out classified storage;Step S3, the original data collected is cleaned and preprocessed;Step S4, big data analysis and mining;Step S5, security vulnerability assessment and classification;Step S6, early warning trigger and notification;Step S7, establish security decision support system, provide reasonable security decision suggestion, the third party vulnerability database is collected, stored and analyzed in the application, realize the accurate detection and evaluation of potential vulnerability of business system, network and application program etc. each aspect, and timely security risk early warning and repair suggestion.
Owner:POWERCHINA HEBEI ELECTRIC POWER SURVEY & DESIGN INST CO LTD

Intelligent detection method for code security vulnerabilities based on large models

PendingCN122389031ALinguistic modelAlgorithm
The present application relates to a large model-based code security vulnerability intelligent detection method. By analyzing the multi-language source code and documents, a standardized business state transition graph is constructed, combined with sandbox simulation to capture real-time state trajectories, to realize the compression of business state key frames and the generation of semantic anchor points, and to integrate them into the large language model input, effectively improving the model's understanding of complex state flow. Further, the model reasoning and rule engine dual-channel collaborative verification logic consistency is adopted, combined with the optimization of the discriminant boundary of the adversarial sample, to improve the vulnerability detection model in a closed loop. While ensuring the detection accuracy, the false positive rate is reduced, and the ability to capture multi-step, multi-semantic business logic vulnerabilities is improved.

Determining security vulnerabilities based on cybersecurity knowledge graphs

Some embodiments may include methods and related systems to receive a query associated with an access level and determine a set of documents based on the query and a knowledge graph, where the set of documents is associated with a set of tags, a set of directives, and a set of criteria. Some embodiments may then determine a score based on the set of directives, determine whether the access level satisfies the set of criteria, and, in response to a result indicating that the access level satisfies the set of criteria, associate a set of text identifiers with the score by tracing the set of tags. Some embodiments may then store, in a set of database records, the score and the set of text identifiers.
Owner:CAPITAL ONE SERVICES LLC

A Generative AI-Based Method for Intelligent Discovery and Risk Assessment of Software Security Vulnerabilities

This invention relates to the fields of software security and artificial intelligence, specifically a generative AI-based intelligent vulnerability discovery and risk assessment method for software security. The method includes: generating abnormal behavior patterns by collecting multi-source data from the target software, inputting this data into a pre-trained generative AI model for multi-level correlation reasoning, and automatically outputting a set of vulnerability descriptions containing location, path, and impact. Historical verification of the vulnerability descriptions enhances their accuracy, and a risk posture assessment is performed. The attack entry point exposure, exploitation path feasibility, and system impact scope of each vulnerability are quantitatively calculated to form a structured risk quantification matrix. Based on this matrix, risk level mapping is completed, and remediation suggestions and priority sequences are automatically generated. Finally, a risk assessment report is integrated and output. This method automates and intelligently discovers vulnerabilities and significantly improves the accuracy and operability of risk analysis through multi-dimensional quantitative assessment.
Owner:BEIJING HUAXIN MEASUREMENT & CONTROL TECH CO LTD

Intelligent software architecture collaborative development method and system

PendingCN122450483AData packSoftware system
The application provides an intelligent software architecture collaborative development method and system, wherein the method is executed by a server and includes the following steps: step S1, constructing a software architecture digital twin model corresponding to a software system in a production environment, collecting runtime data of the software system in the production environment in real time, including performance data, log data and link tracking data; step S2, preprocessing and feature extraction are performed on the collected runtime data to generate a standardized architecture state feature vector; and the architecture state feature vector is input into a pre-trained causal reasoning model to identify performance bottlenecks and security vulnerabilities in the architecture. The application combines architecture design, development, testing and operation and maintenance through digital twin technology, forms a closed loop of perception-analysis-decision-execution-feedback, enables the software architecture to continuously self-optimize according to actual operation data, and realizes architecture life cycle closed loop.
Owner:NANJING RUIDA FENGFAN INFORMATION TECHNOLOGY CO LTD

Hardware-Enforced Agentic GenAI Workflow Orchestrator with Cryptographic Ethical Guardrails and Human-in-the-Loop Escalation for Autonomous Clinical Operations

PendingUS20260188502A1Computer hardwareClinical settings
A hardware-anchored orchestration system for autonomous GenAI agents in clinical settings, implementable in ASIC or FPGA fabric to ensure deterministic enforcement independent of software execution layers. The system utilizes a hardware-isolated ethical supervisor—comprising a HSM or TPM—to monitor agentic workflows against human-configured safety thresholds stored in an ethical guardrail manifest in a silicon vault. Hardware-based logic gates detect statistically anomalous token-level entropy as a causal indicator of hallucination, and bias monitors evaluate equity thresholds against manifest-defined fairness indices. If a safety breach is detected, a hardwired interlock circuit asserts a non-maskable interrupt to block the agent's output before it is committed to the clinical record. The architecture supports multi-agent quorum verification and cryptographic provenance anchoring, ensuring autonomous agentic actions remain compliant with clinical regulatory standards via hardware-verified human oversight and zero-knowledge compliance verification.
Owner:BICKERSTAFF III GEORGE WILLIAM

A deployment method, device and electronic equipment of an application

The application discloses a kind of application deployment method, device and electronic equipment, the method includes: target terminal receives the application package to be deployed that publishing server sends;Determine application configuration parameter based on application package and execute HTTP interface registration operation, and according to the start environment of the application program carried by application configuration parameter to application package Rendering;First instruction is sent to publishing server, to make publishing server execute the gray release process of application after receiving first instruction, and according to the detection result of gray release, control management server provides target traffic for target terminal, completes the deployment of application program.In the above-mentioned mode, dependency and configuration parameter are uniformly encapsulated in application package, and the target terminal can actively load application configuration parameter, without the help of container management, avoiding the problem of dependency redundancy and security vulnerability caused by the introduction of unnecessary container, realizing the containerless application deployment.
Owner:NETSUNION CLEARING CORP

Hot patch injection method, hot patching method and apparatus

This disclosure provides a hot patching injection method applied to a running target process, comprising: identifying a target thread in the target process that is in an interruptible, lock-free state; modifying a first execution environment of the target thread to a second execution environment; wherein the first execution environment is the current execution environment of the target thread, and the second execution environment is used to redirect the execution flow of the target thread to a dynamic library loading interface within the target process; and controlling the target thread to initiate the loading of a hot patching tool library through the dynamic library loading interface. This disclosure also provides a hot patching method, an electronic device, a computer-readable storage medium, and a computer program product. This disclosure enables the injection of hot patching tools without restarting the process, giving the process hot patching functionality, and thus allowing the use of hot patches to fix security vulnerabilities and faults without restarting the process.
Owner:ZTE CORP

A JAR vulnerability detection method, system, storage medium and computer facing a container management platform

ActiveCN116484377BJavaReliability engineering
The application relates to the technical field of computers, in particular to a JAR vulnerability detection method and system for a container management platform, a storage medium and a computer, the method comprises the following steps: compiling and packaging JAVA services, building an image, listening to a container creation event, listening to a container change event, listening to a container stop event and locating JAR, wherein the locating JAR comprises the following steps: traversing a runtime container set, checking an image version of each container ID, checking JAR dependence from the image; the application maintains the image version and JAR dependence and the runtime container ID condition, can realize real-time query of JAR dependence conditions of all currently running containers, facilitates rapid positioning of a container set associated with each JAR, provides rapid and accurate positioning of the container set containing the specific JAR in a non-intrusive mode, and facilitates rapid intervention when a security vulnerability or the like occurs.
Owner:CHINA LIFE ASSET MANAGEMENT CO LTD

Active Agent for Detection of Bridges to an Air-gapped Network

PendingUS20260205488A1Active agentEngineering
The present disclosure relates to a method and system for detecting breaches in air-gapped networks through the use of agent-based software. The agent actively attempts to connect to external services outside the air-gapped network, and if any of these attempts are successful, an alert is triggered. This provides a proactive method for verifying the integrity of network isolation and detecting potential breaches in real-time.

A software security vulnerability intelligent scanning method based on static analysis

PendingCN122331950AProgram graphVulnerability
This invention discloses an intelligent scanning method for software security vulnerabilities based on static analysis, specifically relating to the field of software security testing technology. The method acquires a snapshot of the baseline version source code and a snapshot of the modified version source code corresponding to the software project under test, establishes alignment relationships between program elements of the previous and current versions, and forms a set of modified elements. Combining the baseline version program graph cache, function summary cache, and historical hazard index, a comprehensive quantity of the impact of changes is formed, and a subgraph of the impact of changes is constructed. Static incremental vulnerability analysis is performed on the subgraph of the impact of changes to identify newly added risk paths and activated historical hazard paths, and a trusted comprehensive quantity of risk activation is formed. Based on the trusted comprehensive quantity of risk activation, confirmation screening and baseline updates are performed, and valid incremental alerts or paths awaiting review are output. This invention can narrow the analysis scope, reduce the resource consumption of full scans, and improve the ability to identify incremental vulnerabilities and the activation of historical hazard paths.
Owner:SHANGHAI XUYIN TECHNOLOGY CO LTD

Systems and methods for detecting replay attacks to an authentication system

A REE can approve or deny authentication based on a sensor output signal and a secure element (SE) operatively coupled to the REE can detect a replay attack. A feature extractor produces a feature vector from the sensor output signal. The feature vector can be used to authenticate a user. Detecting the replay attack can include storing previous feature vectors, sending a security breached signal to the REE in response to determining that the feature vector equals one of the previous feature vectors, and storing the feature vector as one of the previous feature vectors. The REE can deny authentication in response to receiving the security breached signal.
Owner:NXP BV

System and method for monitoring security vulnerabilities in software applications with third-party components

A method, system and computer program product for automatically and continuously monitoring security vulnerabilities in software applications with third-party components and reporting newly-discovered vulnerabilities in the third-party software components used by a software application is provided. The method includes receiving a software bill of materials (SBOM) including a plurality of third-party software components; automatically analyzing each of the plurality of third-party software components of the SBOM for known vulnerabilities and generating a first list of known vulnerabilities; storing the first list of known vulnerabilities; automatically analyzing, after a first period of time, each of the plurality of third-party components identified in the SBOM for newly-discovered vulnerabilities; storing a compiled second list of known vulnerabilities; comparing the compiled second list of known vulnerabilities with the original list of known vulnerabilities; and in response to the second list differing from the original list, transmitting, through a network, a notification identifying a set of differences in vulnerabilities between the second list and the original list.
Owner:FUJIFILM HEALTHCARE AMERICAS CORP

Vulnerability management method and device, storage medium and product

PendingCN122087824AImprove repair efficiencyavoid wastingPlatform integrity maintainanceVulnerability managementDynamic data
The invention discloses a vulnerability management method and device, a storage medium and a product, and relates to the technical field of security vulnerability management, and the method comprises the steps: carrying out the multi-dimensional risk assessment of a to-be-managed vulnerability, and obtaining an initial risk score of the to-be-managed vulnerability; collecting dynamic data of to-be-managed vulnerabilities, and updating the initial risk score in real time through the dynamic data to obtain a standard risk score; and sorting the to-be-managed vulnerabilities based on the standard risk scores to obtain a repair priority sequence of the to-be-managed vulnerabilities. According to the method, comprehensive and accurate assessment of the vulnerability risk is realized, the obtained standard risk score fits the threat situation of the vulnerability in real time, the repair resource distribution can be effectively optimized according to the repair priority sequence, the vulnerability management repair efficiency is improved, and the system security risk is remarkably reduced.
Owner:VIPSHOP (GUANGZHOU) SOFTWARE CO LTD

Automated penetration testing methods, apparatus, equipment and storage media

ActiveCN117675313BAutomate executionRealize fine controlSecuring communicationAttackSimulation
This invention discloses an automated penetration testing method, apparatus, device, and storage medium, belonging to the field of penetration testing technology. The invention obtains initial information about a real network environment; inputs this initial information into a preset automated penetration testing agent to obtain target attack actions; loads the target attack actions into the target network environment and receives feedback information from the target network environment; and performs automated penetration testing based on the feedback information. This solution for automated penetration testing does not excessively rely on human resources, enabling automated execution and fine-grained control of the entire sequential penetration testing process, improving the accuracy and adaptability of the test, and thus more effectively identifying potential security vulnerabilities and threats.
Owner:PENG CHENG LAB

Method for electronic security assessment of a building automation system and building automation system

Methods and systems for performing an electronic security assessment of a building automation system are provided. The building automation system includes a controller and a network of electronic devices that are electronically communicatively connected. The method includes requesting, by the controller via a secure channel, an electronic security scan of the controller with a data set of the controller from a cloud-based service. The method also includes initiating the electronic security scan of the controller based on the data set of the controller. The method also includes electronically assessing security vulnerabilities of the building automation system. The method also includes electronically assessing, by the controller, security vulnerabilities of the network of electronic devices that are electronically communicatively connected with the controller. The method also includes determining a list of recommendations for addressing the security vulnerabilities of the building automation system based on the electronically assessed security vulnerabilities.
Owner:TRANE INTERNATIONAL INC

Automated system to assess network systems security, exploit vulnerabilities, and provide security recommendations

A network system to use artificial intelligence to provide an automated system to identify security vulnerability exploitation paths, predict next targets, and provide recommendations. The system provides a centralized system to provide an automated system to perform each primary function of red-teaming activities and penetration testing. The system provides the following actions to test the system: automated attack surface discovery; automation of penetration testing either internal or external; automation of different cloud security scanning; and automation of network and web scanning. To accomplish these steps, the system analyzes information gathered related to a client security posture and recommends required assessments, automates the implementation of the security assessments to identify security vulnerability exploitation paths, ranks vulnerabilities, removes false positives, suggests next actions, and predicts next targets.
Owner:CYBRAL IP LLC

Automated application programming interface (API) testing

Various embodiments facilitate Application Programming Interface (APIs) testing. In some examples, an apparatus detects security vulnerabilities in an API. The apparatus comprises one or more computer-readable storage media, a processing system operatively coupled with the one or more computer-readable storage media, and program instructions stored on the one or more computer-readable storage media. When executed by the processing system, the program instructions direct the processing system to perform operations. The apparatus monitors API traffic and responsively generates contextual information that characterizes the operations of the API. The apparatus generates an API test based on the contextual information to detect the security vulnerabilities in the API. The apparatus executes the API test on the API. The apparatus generates test results that indicate detected security vulnerabilities in the API. The processing system exports the test results.
Owner:CEQUENCE SECURITY INC

Identity exposure surface reduction

Existing security methods fail to dynamically account for inactive users, creating a persistent security vulnerability. The disclosed embodiments automatically protect credentials that are cached on a computing device. This improves the security of the computing device by limiting the number of credentials that are exposed when the device is compromised. In some configurations, historical usage data is analyzed to determine which credentials to protect, such as the credentials of users deemed inactive on the device. Historical usage data may be obtained from event logs stored on the device or the authentication server. Credentials may be protected by encrypting them or by removing them from the device. In some configurations, other types of sensitive information such as browser cookies, saved browser passwords, sensitive files, or documents may also be removed for inactive users.
Owner:MICROSOFT TECHNOLOGY LICENSING LLC

Access point port security system

ActiveUS12671995B1Tamper resistanceAuto-configuration
Access point network equipment has communication ports that allow communications with other network components and a cloud based AP device management system having an Auto Configuration Service (ACS). Communications cables coupled to ports can be easily removed and replaced with unauthorized devices that have access to the network creating a security breach. When an authorized cable or plug is removed from a port, a link down event can be detected by tamper detection software running on the access point network equipment and the link down event information can be transmitted to the cloud / Map service. When a link down events is detected, the cloud / ACS transmits instructions to the access point network equipment to perform various possible security actions to protect the network.
Owner:CALIX INC

Method for detecting security vulnerabilities of a cpu card based on side channel communication analysis

The application provides a CPU card security vulnerability detection method based on side channel communication analysis, comprising radio frequency signal sniffing and original data packet capturing, original data processing based on triple clue filtering method, interactive data security analysis based on characteristic factors and security analysis result output. The application realizes accurate detection and quantitative evaluation of CPU card security vulnerabilities through passive sniffing, data repair, feature extraction, multi-dimensional security analysis and optional replay verification, realizes accurate repair and feature extraction of sniffed data through the triple clue filtering method, forms a self-optimizing iteration mechanism combined with machine learning, establishes a quantitative security analysis system from two dimensions of random number properties and encryption correlation, and realizes full-dimensional and accurate detection of CPU card security vulnerabilities in cooperation with the replay verification.
Owner:TOEC ANCHEN INFORMATION TECH