Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

615 results about "Security bug" patented technology

A security bug or security defect is a software bug that can be exploited to gain unauthorized access or privileges on a computer system. Security bugs need not be identified nor exploited to qualify as such.

Ai-based cybersecurity system and method thereof

An AI-based Cybersecurity System and Method enable real-time detection, analysis, and mitigation of cyber threats within computing networks using adaptive artificial intelligence. The system continuously monitors network traffic, extracts behavioral and contextual attributes, and applies deep learning-based inference to identify anomalous activities indicating security breaches. The method integrates several computational units, including a network monitoring unit, feature extraction unit, artificial intelligence processor, contextual reasoning processor, and decision synthesis unit, to compute a composite risk index quantifying threat likelihood and severity. A classification processor categorizes detected threats into types such as ransomware, phishing, or unauthorized access, while a mitigation control processor initiates automated response actions to isolate compromised nodes and restore network integrity. An adaptive learning processor updates AI models using feedback from confirmed incidents. This provides a scalable, self-evolving cybersecurity framework that minimizes human intervention and enhances resilience against dynamic and zero-day threats.
Owner:PELL REDDY RAJENDER REDDY

Dynamic and static combined detection method for security vulnerabilities of power system software

The invention is applicable to the technical field of vulnerability detection, and provides a power system software security vulnerability dynamic and static combined detection method, which comprises the following steps: acquiring static source code data of power system software and dynamic behavior log data during operation; generating a hierarchical abstract syntax tree and structured time series data; performing multi-dimensional feature extraction on the static source code data and the dynamic behavior log data based on a vulnerability knowledge graph of the power system; generating a domain constraint confrontation sample based on the power protocol features and the abnormal features during operation, and inputting the domain constraint confrontation sample into the constructed hybrid detection model for confrontation training to obtain a trained hybrid detection model; and performing automatic detection on the power system software by utilizing the trained hybrid detection model, and outputting a detection result containing a static code defect position and a dynamic attack path. The full-life-cycle accurate detection of the software vulnerability of the power system is realized, and the network security protection capability of the power system is improved.
Owner:GUANGXI POWER GRID CORP

Streaming knowledge injection and adversarial self-optimization large language model training method and system

The invention discloses a streaming knowledge injection and adversarial self-optimization large language model training method and system, and the method comprises the steps: collecting the newest knowledge of an authoritative information source in real time, converting the newest knowledge into a structured constraint rule through a semantic analyzer, and dynamically updating a knowledge base; based on the updated knowledge base, adopting a PPO algorithm to optimize a generator, actively constructing a high-risk adversarial sample, and forcing the model to expose security vulnerabilities; after user input and adversarial samples are input into the model, total loss is calculated through constraint detection, gradient updating is blocked if the total loss exceeds a threshold value, and otherwise, a multi-level safety verification stage is started; and finally, fusing a security verification result and the adversarial loss, updating a total loss function and cooperatively adjusting model parameters to form a continuous self-optimization training cycle. According to the method, compliance is guaranteed through streaming knowledge injection, vulnerabilities are actively mined in combination with adversarial training, verification precision is improved by means of multi-level detection and dynamic threshold adjustment, and safety and reliability of a large language model in a complex scene are enhanced.
Owner:LANZHOU UNIV

Generative ai ops for cyber security threat detection

ActiveUS20250317464A1Securing communicationIndustrial securityIndustrial safety system
An industrial security system leverages generative artificial intelligence (AI) to automate the process of identifying software or hardware insecurities on industrial assets, generate recommendations for mitigating these vulnerabilities, and, where appropriate, deploy countermeasures to the vulnerable assets. By leveraging automated asset discovery, real-time asset and network monitoring, and generative AI-assisted vulnerability detection and remediation, the system can reduce the amount of time spent by security administrators in identifying and closing security vulnerabilities within their plant environments, and can alert administrators of potential security issues before those issues become critical.
Owner:ROCKWELL AUTOMATION TECH INC

Virtual Computer Model-Based Fuzz Testing System and Method

The present invention provides a fuzz testing system and method based on a virtual computer model. Traditional fuzz testing approaches primarily modify external inputs to detect security vulnerabilities, making it difficult to monitor internal state changes in real-time. This invention constructs a test environment using a virtual computer model and incorporates automatic assertion generation and detection functions, enabling precise analysis of both internal and external signals of the system. After executing fuzz testing, assertion data is analyzed to assess test coverage and identify untested code regions, allowing for an optimized testing strategy. This improves the detection rate of security vulnerabilities, enhances test automation and reliability, and can be applied in various fields such as networks, automotive ECUs, IoT, finance, aerospace, and semiconductors.
Owner:AXION CO LTD

Security vulnerability management method and system based on big data

The invention relates to the technical field of security vulnerability analysis, in particular to a big data-based security vulnerability management method, which comprises the following steps of: constructing a real-time data acquisition strategy, capturing an internal source network equipment log, a server running state and application system flow data through a distributed log collection component, and storing the internal source network equipment log, the server running state and the application system flow data; meanwhile, vulnerability information of the exogenous threat intelligence platform is synchronized through an API interface; constructing a dynamic risk assessment model, and updating the risk assessment of the security vulnerability in real time by taking the four-dimensional model [IP address, service type, port number and software version] as a reference; and triggering a response strategy according to risk value grading, wherein the response strategy comprises automatic isolation of high-risk equipment, dynamic configuration of firewall rules and generation of a repair work order. According to the invention, through the synergistic effect of real-time data acquisition, dynamic asset modeling, intelligent risk assessment, a hierarchical response mechanism and a closed-loop verification system, the accuracy, efficiency and defense capability of security vulnerability management are significantly improved.
Owner:ZHENGZHOU BIG DATA DEV CO LTD

Artificial intelligence model traceability and tamper-proofing method and system based on block chain enhancement

The invention discloses an artificial intelligence model traceability and tamper-proofing method and system based on block chain enhancement, and relates to the technical field of artificial intelligence model traceability and tamper-proofing. According to the technical key points, the method comprises the following steps: carrying out simulation attack by utilizing penetration testing to obtain multi-type data containing security vulnerability data; preprocessing the multi-type data; constructing an anomaly detection and attack recognition model based on a variable parameter neural network, and training the anomaly detection and attack recognition model based on the preprocessed data; performing Merkle tree encryption on the preprocessed data and model parameters obtained by training, encoding model prediction output, embedding the encoded model prediction output into a Merkle tree structure, and completing recording on a block chain through an intelligent contract; and for a to-be-evaluated artificial intelligence model, calling the global root hash value on the block chain for verification. According to the invention, the whole process of the artificial intelligence model from data acquisition to reasoning output is verifiable, traceable and tamper-proof.
Owner:XIAN XINGCHEN CLOUD DATA TECH CO LTD

Actionable artificial intelligence bot for data security correlations

Techniques are described for techniques for an actionable artificial intelligence bot based on data security correlations. An example method comprises determining, by a data platform implemented by a computing system, a plurality of tags for a snapshot executed by the data platform, detecting, by the data platform, an indication of a security breach relating to the snapshot, processing, by the data platform and using a machine learning model, a plurality of attributes of the security breach and the plurality of tags to identify a potential compromise of the snapshot, processing, by the data platform and using a large language model, at least the plurality of attributes to generate an actionable prompt including a natural language description of at least one security response, and outputting, by the data platform, the actionable prompt.
Owner:COHESITY INC

Providing user-induced variable identification of end-to-end computing system security impact information systems and methods

Systems and methods for providing user-induced variable identification of end-to-end computing system security impact information via a user interface are disclosed. The system receives at a graphical user interface (GUI), a user calibration of a graphical security vulnerability element. The system then determines a set of computing system components that interact with data associated with the network operation based on a transmission of the network operation associated with a computing system. The system then determines a set of security vulnerabilities associated with each computing system component of the set of computing system components using a third-party resource. The system then applies a decision engine on the set of security vulnerabilities to determine a set of impacted computing-aspects associated with the set of computing system components. The system then generates for display a graphical representation of the set of impacted computing-aspects satisfying the security condition of the user calibration.
Owner:CITIBANK N A

Large visual language model vulnerability detection method and device based on security sensitive layer activation guidance and storage medium

The invention discloses a large visual language model vulnerability detection method and device based on security sensitive layer activation guidance and a storage medium, and belongs to the technical field of artificial intelligence security, the method comprises the following steps: S1, constructing a security sensitive layer activation induction sample data set; s2, performing quantitative analysis on activation differences of the model intermediate layer under attack and normal input; s3, on the basis of the recognized security sensitive layer combination and an output layer of the large visual language model, generating an in-process confrontation image with an attack attribute through optimization of a loss function; and S4, recording an optimal security sensitive layer combination and a harmful response path guided by the optimal security sensitive layer combination, and constructing a structured representation of the potential security vulnerabilities of the model. According to the method, the security fragile links of the model are accurately positioned, the attack guiding force is improved in combination with multiple losses, the generated confrontation disturbance is controllable and imperceptible, the good cross-instruction migration capability is achieved, and the method adapts to various security assessment and red team test tasks.
Owner:NANJING UNIV OF SCI & TECH

Code generation method and device based on large model, equipment, medium and product

The invention discloses a code generation method and device based on a large model, equipment, a medium and a product, and the method comprises the steps: carrying out the code generation through a first code large model according to target code demand data, and obtaining an initial code; according to the first code snippet, generating a test code through a second code large model to obtain a unit test code; according to the unit test code and the initial code, code repair based on editing distance regularization is conducted through a third code large model, and a to-be-analyzed code is obtained; performing iterative optimization on the to-be-analyzed code and the unit test code to obtain a target code corresponding to the target code demand data; according to the method, code generation, unit test generation and code repair are carried out in a multi-model cooperation mode, the reliability and accuracy of code generation can be effectively improved, software security vulnerabilities are reduced, and therefore the stability and security of a software system are improved.
Owner:CHINA MOBILE (SUZHOU) SOFTWARE TECH CO LTD +1

System and method for midserver facilitation of mass scanning network traffic detection and analysis

A system and method that uses midservers located between an enterprise network and an external network to provide mass scanning network traffic detection and analysis capabilities for the enterprise network. The midserver may be loaded with configurations that allow it to operate as a mass scan event detector capable of detecting network sniffers, botnets, and malicious peer-to-peer connections which can lead to security vulnerabilities. In such configurations, midserver may receive and analyze network traffic to determine if the network traffic is suspicious based on heuristic and signature-based techniques, and then generate an appropriate response action which can be implemented to mitigate the risk.
Owner:QOMPLX INC

Log file-based security vulnerability AI positioning method and system

The invention relates to the technical field of network security, and discloses a security vulnerability AI positioning method and system based on log files. The method comprises the following steps: firstly, analyzing user feedback describing open source component security vulnerabilities to extract fault key entity information, screening related log entries based on the fault key entity information, and constructing a vulnerability propagation graph; identifying a vulnerability triggering initial point set by using a graph traversal algorithm and a graph neural network, calling a component vulnerability case library to deduce a vulnerability utilization propagation chain and calculating a matching degree with a known open source component vulnerability utilization chain feature, and obtaining a maximum probability vulnerability utilization propagation chain and an associated vulnerability triggering initial point set; and generating a root cause positioning report, and updating the knowledge base or model training data according to a user verification result. According to the method, the initial vulnerability point and the complete vulnerability propagation chain of the security vulnerability of the open source component can be accurately and efficiently positioned, and the positioning accuracy and timeliness are improved.
Owner:JIANGSU ZHUOYI INFORMATION TECH CO LTD +2

Text-based tagging of security deficiencies using generative machine learning models

Techniques for determining a tag for a security deficiency (e.g., a security vulnerability and / or exposure) using a generative machine learning model. In examples, a system may perform the following operations: (i) identifying a deficiency identifier associated with the security deficiency, (ii) retrieving one or more texts that correspond to the deficiency identifier, (iii) generating a prompt for a generative model to process the text(s) to detect a tag, (iv) providing the prompt to the generative machine learning model, (v) receiving the output of the machine learning model, (vi) determine whether the output satisfies one or more output constraints (e.g., one or more output constraints specified by format and / or content requirements specified in the prompt), and (vii) if the output satisfies the output constraint(s), determine the tag based on the validated output.
Owner:CISCO TECHNOLOGY INC

Automatic use case construction method and system for private protocol test

The invention discloses an automatic use case construction method and system for private protocol testing, and relates to the technical field of communication protocol testing. Comprising the following steps: step 1, identifying a field structure, a state conversion rule and a dependency relationship of a private protocol through traffic sniffing and deep packet analysis; step 2, dynamically generating a test case set covering a normal scene, a boundary scene and an abnormal scene based on a reinforcement learning algorithm in combination with a protocol state machine and a historical test result; and step 3, injecting the generated test flow in the simulation environment, monitoring response data of the target system in real time, calculating and adjusting an evaluation value, and adjusting a generation strategy of the test case according to the value. Through adaptive execution and multi-dimensional anomaly analysis in the simulation environment, the test strategy is adjusted in real time, logic errors, resource leakage and security vulnerabilities are accurately recognized, efficient robustness verification of the private protocol is achieved, and the test efficiency and protocol security are remarkably improved.
Owner:SHANGHAI ANBAN INFORMATION TECH CO LTD

Multi-protocol integration method and device, equipment, storage medium and program product

The invention relates to a multi-protocol integration method and device, equipment, a storage medium and a program product, which are applied to a bastion host, and the bastion host comprises a communication port. The method comprises the following steps: firstly, receiving a first access request generated based on a first protocol and sent by each client through a communication port, then, determining target equipment needing to be accessed by each client according to the first access request, then, determining a second protocol supported by each target equipment based on preset configuration of each target equipment, and finally, sending the second protocol to the client through the communication port. And converting each first access request based on the first protocol and the second protocol, determining a second access request of each client, and accessing the corresponding target device through the second access request. By adopting the method, the number of communication ports can be reduced, so that the network attack surface is reduced, potential security holes and threats are reduced, and the access security of the target equipment is improved.
Owner:CHINA TELECOM CLOUD TECH CO LTD

Software source code security vulnerability detection method based on artificial intelligence large model

The invention discloses a software source code security vulnerability detection method based on an artificial intelligence large model, and belongs to the technical field of information security and source code detection, and the method comprises the following steps: carrying out user registration and login, uploading a file, judging whether static analysis is carried out or not, judging whether dynamic analysis is carried out or not, introducing the AI large model, and generating a detection report; according to the method, through multi-level technology integration and a self-evolution mechanism, normal form innovation of vulnerability detection from a single view angle to global perspective is realized. According to the system, on the basis of unified intermediate representation, a closed-loop architecture of static rule screening, dynamic behavior verification and AI semantic reasoning is constructed, and the core contradiction of high false alarm rate, insufficient path coverage and semantic understanding deficiency of a traditional method is effectively solved.
Owner:JINLING INST OF TECH

Security vulnerability detection method and device, computer program product and storage medium

The invention discloses a security vulnerability detection method and device, a computer program product and a storage medium, and belongs to the field of code detection.A structured graph of a to-be-detected code can be constructed according to structured information of the to-be-detected code, and then the to-be-detected code is coded to obtain a text coding vector; and coding the structured graph of the to-be-detected code to obtain a structured coding vector, and finally inputting the comprehensive vector into a pre-trained detection model so as to obtain a security vulnerability detection result. The problem of how to reduce the omission ratio and the false alarm rate of security vulnerability detection of codes is solved, and the beneficial effects that security vulnerability detection is performed from two dimensions of semantics of code texts and semantics of structured information, and the omission ratio and the false alarm rate of security vulnerability detection of codes are reduced are achieved.
Owner:INSPUR SUZHOU INTELLIGENT TECH CO LTD

Mobile application security assessment and automatic detection method

The invention relates to the field of application security detection, and provides a mobile application security assessment and automatic detection method, which adopts a data processing technology based on artificial intelligence to carry out syntactic analysis and semantic understanding on an obtained code of a mobile application program so as to obtain a code semantic structured coding feature. Meanwhile, semantic embedding coding is carried out on a set of security vulnerability rules extracted from the security vulnerability rule base to obtain a set of security vulnerability rule semantic embedding coding features; then, a detection result is automatically obtained based on dynamic query analysis representation of a set of code semantic structured coding features and security vulnerability rule semantic embedded coding features, and a security alarm prompt is generated in response to the detection result under the condition that the confidence coefficient of security vulnerabilities in the mobile application program exceeds a preset threshold value. In this way, the accuracy and reliability of the security vulnerability detection result can be effectively improved.
Owner:STATE GRID HENAN INFORMATION & TELECOMM CO

Intelligent detection method and system for security vulnerabilities of terminal layer of power internet of things

The invention discloses an intelligent detection method and system for security vulnerabilities of a terminal layer of an electric power internet of things, and relates to the technical field of security protection of the electric power internet of things, and the method comprises the steps: collecting multi-dimensional information and network traffic characteristics of terminal equipment of the electric power internet of things, constructing an equipment fingerprint database, carrying out the comparison verification of the equipment, and obtaining a security vulnerability of the terminal layer of the electric power internet of things according to a verification result; the method comprises the following steps: classifying network traffic, identifying an abnormal traffic sequence, extracting behavior parameters of network traffic abnormity and network access abnormity, carrying out association analysis on the abnormal parameters, labeling equipment, and generating a security vulnerability detection report. The technical problem that potential security vulnerabilities are difficult to find and repair in time due to the fact that complex abnormal behaviors in a device layer and network traffic cannot be effectively recognized and handled in the prior art is solved, real-time and accurate security vulnerability detection is achieved by constructing a device fingerprint database and carrying out traffic classification and abnormal behavior analysis, and the security vulnerability detection efficiency is improved. Therefore, the technical effect of improving the security of the terminal layer of the power Internet of Things is achieved.
Owner:GUANGZHOU KETENG INFORMATION TECH

Code-level security vulnerability detection method, electronic equipment and storage medium

The invention relates to the technical field of vulnerability detection, in particular to a code-level security vulnerability detection method, electronic equipment and a storage medium. The method comprises the steps of obtaining a logic graph corresponding to a target code, wherein the logic graph comprises a role node, a service entity node, an operation edge and an access constraint edge; obtaining an application scene label of the target code according to the logic graph; inputting the target code into an AST resolver to obtain a syntax tree corresponding to the target code; obtaining a sensitive function library B and a suppression function library C matched with the target code according to the application scene label of the target code; and judging whether the target code has security vulnerabilities or not according to the syntax trees corresponding to the B, the C and the target code. According to the method, the unauthorized risk vulnerabilities in the program codes can be effectively identified.
Owner:QINGDAO WANDAO (BEIJING) INFORMATION TECH CO LTD

Dynamic access control method, device and equipment of baseboard management controller, and storage medium

The invention discloses a dynamic access control method and device of a baseboard management controller, equipment and a storage medium, and relates to the technical field of server hardware security management.The method comprises the steps that when an access request is detected in a trusted operation environment, multi-dimensional context attributes associated with the access request are collected; performing dynamic trust evaluation based on the multi-dimensional context attribute, and generating a dynamic trust score corresponding to the access request; and executing an access control decision corresponding to the access request according to the dynamic trust score. Compared with a traditional static trust model, the dynamic trust evaluation is carried out based on the multi-dimensional context attribute under the trusted operation environment of starting verification of the baseboard management controller, and the differentiated access control decision is executed according to the dynamic trust score, so that the access risk is accurately identified, and the reliability of the system is improved. The security vulnerability of'permanent trust in one-time authentication 'in the prior art is avoided, and the access security of the substrate management controller is improved.
Owner:中电长城科技有限公司

Quantum key distribution network situation assessment method, device, equipment and medium

The embodiment of the invention provides a quantum key distribution network situation assessment method and device, equipment and a medium. The method comprises the following steps: acquiring performance data of a quantum key distribution network; the performance data comprises network structure data, key performance data, communication quality data, data transmission data and an evaluation model; determining a comprehensive influence factor according to the performance data; the comprehensive influence factor is used for reflecting the importance degree of the performance data to the quantum key distribution network situation; and according to the performance data, the comprehensive influence factor and the evaluation model, determining the situation of the target quantum key distribution network, thereby significantly improving the security and reliability of the QKD network. Potential security vulnerabilities and attack risks can be found and coped with in time through evaluation of the network situation, and the security and high efficiency of the key distribution process are ensured.
Owner:中电信量子信息科技集团有限公司 +1

Intelligent security method and system based on Internet of Things

The invention relates to the technical field of intelligent security and protection, in particular to an intelligent security and protection method and system based on the Internet of Things, and the method comprises the following steps: obtaining a bioelectrical impedance signal generated when a user touches an access control sensing area, identifying a current response condition of a differentiated frequency band, matching stored user data, analyzing the continuity of an electrical impedance parameter, and screening abnormal fluctuation data. And the fluctuation frequency and the variation amplitude in a short time are identified, and a bioelectrical impedance matching value is obtained. According to the invention, through comprehensive analysis of the electrical impedance parameters and the gait data, the individual identity can be identified and verified more accurately, the protection capability for unauthorized access is improved, through careful monitoring of physiological and behavioral characteristics, the security is significantly improved, and the stability and reliability in various environments can be adjusted and improved according to environmental changes. The capability of preventing potential security threats is enhanced for risk assessment of abnormal behaviors, and generation of security vulnerabilities is effectively prevented by monitoring behavior deviation in the identity verification process in real time.
Owner:深圳市五兴科技有限公司

Intelligent analysis-based security vulnerability intelligent research and judgment and co-processing system and method

The invention discloses an intelligent analysis-based security vulnerability intelligent research and judgment and co-processing system and method, and relates to the technical field of network security, and the system comprises a multi-source data collection module which obtains security data in real time by adopting a multi-level intelligent hierarchical collection architecture; the intelligent analysis module adopts a three-level progressive analysis architecture to analyze and collect data; the intelligent agent scheduling module designs a unified control framework, realizes standardized management and control of security equipment through hierarchical abstraction, receives analysis results, integrates a self-adaptive scheduling algorithm based on multi-objective optimization and an alarm vulnerability intelligent circulation strategy relying on an optimization mechanism of the self-adaptive scheduling algorithm, and executes a security mechanism by means of an adapter factory mode, a strategy arrangement engine and a four-level execution guarantee mechanism. Equipment self-adaptive management, strategy intelligent scheduling and vulnerability grading processing are supported, and a processing result is fed back; and the report generation and evidence collection module displays the disposal result and automatically generates an electronic evidence collection package meeting the standard. According to the invention, intelligent research and judgment of vulnerabilities and automatic generation of disposal suggestions can be realized.
Owner:SHANDONG LANGCHAO YUNTOU INFORMATION TECH CO LTD

Systems and methods for determining a security vulnerability of a computer system

Systems, apparatuses, methods, and computer program products are disclosed for determining a security vulnerability of a computer system. An example method includes initializing a policy based on initial policy data. The example method further includes selecting an action based on the policy and executing, by agent circuitry, the action in the environment. The example method further includes, subsequent to executing the action in the environment, receiving an observation of the environment and determining an updated state from the set of states based on the observation. The example method further includes determining, by the policy, a reward based on the updated state and updating the policy based on the updated state.
Owner:WELLS FARGO BANK NA

Method of managing information security program maturity

Disclosed is a method of more effectively managing and displaying an Information Security Management System (ISMS), or Cybersecurity Framework, by an application executing on a computer device for computing and displaying real time dynamic metrics and market comparison for the User. The method includes authenticated and authorized Users to conduct security baselines based on industry accepted standards in order to establish a plurality of metric baselines dynamically and in real time. The method further includes projects submitted to be measured against organizational goals and simulate the impact to the Security baselines. The method further includes the ability to provide financial visibility into the financial exposure of a Security Breach, or Data exfiltration and other available financial metrics. The method further includes a platform by which companies may request Virtual CISO's services from a pool of executive level resources.
Owner:V3 CYBERSECURITY INC

Cybersecurity vulnerability detection with artificial intelligence models

The present disclosure provides techniques for red teaming with artificial intelligence (AI) models. A processing device generates, via a first AI model, an agent action space based on security data, where the agent action space is indicative of actions to perform to potentially compromise at least one of a computing system, a network, or an application. The processing device performs a reinforcement learning process with an agent based on the agent action space to obtain a log of the reinforcement learning process. The processing device generates, via a second AI model, a report based on the security data and at least a portion of the log, where the report is indicative of a security weakness of the at least one of the computing system, the network, or the application.
Owner:CROWDSTRIKE

Formal verification method based on hierarchical verification framework

The invention discloses a formal verification method based on a hierarchical verification framework, which comprises the following steps of: firstly, dividing a target program into a C code and an assembly code, modeling and verifying the assembly code, then modeling and verifying the C code, and in the modeling process of the C code, carrying out verification on the C code; and defining a specific state and an abstract state of each data structure, establishing mapping through a refinement relationship, defining a function model based on the abstract state, constructing a function API specification, and finally defining system properties for a target program according to the function model and verifying the system properties. According to the method, a hierarchical verification framework and a formalization tool are combined, formalization verification is carried out on the target program from specific implementation to abstract division into three layers, comprehensive verification from bottom-layer codes to high-layer system properties is realized, the risk of security vulnerabilities is reduced, and the reliability of the target program is improved.
Owner:UNIV OF ELECTRONICS SCI & TECH OF CHINA

Systems and methods for threat detection and warning

The present disclosure relates generally to computer security, and, more particularly, to systems and methods for assisting a user in avoiding the accidental disclosure of confidential or sensitive information, as well as avoiding potential security breaches, including phishing and impersonation, malware, and security issues, particularly with respect to websites and electronic communications.
Owner:MIMECAST SERVICES LTD