Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

22 results about "Security operations center" patented technology

A security operations center (SOC) is a centralized unit that deals with security issues on an organizational and technical level. A SOC within a building or facility is a central location from where staff supervises the site, using data processing technology. Typically, a SOC is equipped for access monitoring, and controlling of lighting, alarms, and vehicle barriers.

Network threat systematic protection method

PendingCN121966996ASecuring communicationSecurity operations centerData aggregator
The invention discloses a network threat systematic protection method, and belongs to the technical field of network security. According to the method, a unified policy center is constructed, and three layers of security policies of an overlay network, a terminal and an application are defined and issued in a unified manner; network admission control, terminal security management and API risk monitoring systems are deployed to execute strategies respectively; an intelligent linkage mechanism is established, and cross-system automatic co-processing is realized; centralized monitoring, data aggregation and visual analysis are carried out through the unified safety operation center, and support is provided for optimization; and continuously optimizing the strategy and the rule based on the operation data. According to the invention, the problems of isolation, strategy splitting and response lag of a protection system in the prior art are solved, and an active defense system with cooperative linkage and continuous evolution is constructed.
Owner:GUANGZHOU CHANGBENHENG NETWORK TECHNOLOGY CO LTD +1

DNS security operation center insights

PCT designated stageWO2026024337A9Digital data protectionInternal/peripheral component protectionDomain nameSecurity operations center
Various techniques for DNS security operations center insights are disclosed. In some embodiments, a system / process / computer program product for DNS security operations center insights includes collecting Domain Name System (DNS) security associated events; generating a plurality of insights based on the collected DNS security associated events; and performing an action based on one or more of the insights.
Owner:INFOBLOX INC

Automobile information safety protection method and device based on multi-level protection mechanism, equipment and storage medium

The invention discloses an automobile information safety protection method and device based on a multi-level protection mechanism, equipment and a storage medium, and relates to the technical field of new energy automobiles. At least one of external communication protection configuration, internal communication protection configuration, hardware protection configuration and software protection configuration of a vehicle is detected; and generating a protection detection result, thereby performing real-time monitoring and deep analysis on the network traffic, the host behavior and the vehicle network state, and feeding back the obtained monitoring analysis result to the cloud security operation center, so as to respond to an abnormal event in time, realize comprehensive perception and dynamic evaluation of the vehicle information security state, and improve the safety of the vehicle. Multiple threats such as external attacks, internal tampering, hardware vulnerabilities and software risks are effectively identified, and in combination with cloud collaborative response, early warning is performed on security incidents, so that the adaptive adjustment capability of a protection strategy is remarkably enhanced, the probability of occurrence of security incidents is reduced, and vehicle operation security and user data privacy are guaranteed.
Owner:DONGFENG LIUZHOU MOTOR

Methods and systems for efficient adaptive logging of cyber threat incidents

ActiveUS12603862B2Securing communicationData packCyber threat intelligence
A packet-filtering network appliance such as a threat intelligence gateway (TIG) protects TCP / IP networks from Internet threats by enforcing certain policies on in-transit packets that are crossing network boundaries. The policies are composed of packet filtering rules derived from cyber threat intelligence (CTI). Logs of rule-matching packets and their associated flows are sent to cyberanalysis applications located at security operations centers (SOCs) and operated by cyberanalysts. Some cyber threats / attacks, or incidents, are composed of many different flows occurring at a very high rate, which generates a flood of logs that may overwhelm computer, storage, network, and cyberanalysis resources, thereby compromising cyber defenses. The present disclosure describes incident logging, in which a single incident log efficiently incorporates the logs of the many flows that comprise the incident, thereby potentially reducing resource consumption while improving the informational / cyberanalytical value of the incident log for cyberanalysis when compared to the component flow logs. Incident logging vs. flow logging can be automatically and adaptively switched on or off depending on the combination of resource consumption and informational / cyberanalytical value.
Owner:CENTRIPETAL NETWORKS INC

System and method for dynamic network security risk identification based on multi-source information and ai driving

The application relates to the technical field of network security, and discloses a dynamic network security risk identification system and method based on multi-source intelligence and AI driving, which comprises a dynamic attack graph modeling module, an AI-driven attack simulation engine and a cooperation module.The modeling module fuses multi-source heterogeneous intelligence to construct a network attack graph and calculate node intelligence confidence; the AI engine takes the confidence into a state space, uses a dynamic entropy mechanism to real-time adjust the randomness of reinforcement learning exploration to accurately simulate an attack path; and the cooperation module links external attack surface management and a security operation center to execute closed-loop feedback verification of automatic defense response and path elimination.The application establishes a mapping relationship between intelligence confidence and exploration strategy, effectively solves the problems of uneven multi-source data quality and unknown path missing report, realizes an automatic closed loop from risk perception, simulation deduction to effect verification, and significantly improves risk identification accuracy and response timeliness.
Owner:CSG EHV POWER TRANSMISSION

Remote monitoring of a security operations center (SOC)

ActiveUS12652315B2Security arrangementSecuring communicationSecurity operations centerBusiness enterprise
Systems and methods for remote monitoring of a Security Operations Center (SOC) via a mobile application are provided. According to one embodiment, a management service retrieves information regarding multiple network elements that are associated with an enterprise network and extracts parameters of the monitored network elements from the retrieved information. The management service prioritizes the monitored network elements by determining a severity level associated with security-related issues of the network elements and generates various monitoring views that summarize in real time various categories of potential security-related issues detected by the SOC. Further, the management service assigns a priority to each monitoring view and displays a video on the display device that cycles through monitoring views in accordance with their respective assigned priorities.
Owner:FORTINET INC

Real-time automated extraction of campaign CTI from threat reports

PendingUS20260149741A1Semantic analysisComputer security arrangementsSecurity operations centerEngineering
A pipeline has been created that leverages artificial intelligence and machine learning to efficiently extract information from CTI reports obtained from various sources and yielding information that assists security analysts / threat teams (e.g., security operations centers (SoCs)) and improving the quality of CTI. The “CTI analysis pipeline” employs generative artificial intelligence (“genAI”) to summarize a collection of CTI threat reports and extract threat-related information including TTPs from the CTI reports. Relationships among the threat reports are determined based on the extracted threat-related information and encoded in a graph structure. Graph embeddings based on the relationships encoded in the graph structure and semantic embeddings from the report summaries are combined and the combined embeddings are clustered. The resulting clusters and trained clustering model can be used in various ways to improve CTI, such as determining malicious campaigns, augmenting existing campaign information, and detecting new IOCs and TTPs for existing campaigns and new campaigns.
Owner:PALO ALTO NETWORKS INC

DNS security operation center insights for mass spreading detection

Various techniques for DNS security operations center insights for mass spreading detection are disclosed. In some embodiments, a system / process / computer program product for DNS security operations center insights for mass spreading detection includes collecting Domain Name System (DNS) security associated events; generating a plurality of insights based on the collected DNS security associated events, wherein at least one of the plurality of insights includes a mass spreading detection insight; and performing an action based on one or more of the insights including the mass spreading detection insight.
Owner:INFOBLOX INC

Real-time security threat detection and dynamic response at edge security operations center in o-ran systems

PCT designated stageWO2026095970A1Security arrangementSecuring communicationAccess networkSecurity operations center
Embodiments disclosed herein provide a method and system for detecting real-time security threats by a security management engine deployed at an edge network entity in an open radio access network (O-RAN) system and implementing dynamic security policy in real-time and isolating services or components at system level. The method includes receiving input data from one or more target network entities by the security management engine deployed at the edge network entity. The security management engine compares one or more parameters of the input data with pre-defined reference parameters to identify anomalies. Based on the comparison, the method includes detecting an anomaly corresponding to at least one target network entity, in real-time by the security management engine. Upon detecting an anomaly, a real-time response may be implemented by applying a dynamic policy on an affected component and isolating the affected component.
Owner:RAKUTEN MOBILE INC +1

Machine learned alert classification system

ActiveUS12615281B2Machine learningSecuring communicationSecurity operations centerEngineering
Disclosed herein are systems, methods, and processes for a machine learned alert triaging classification (ATC) system that uses machine learning techniques to generate an alert triage classification model that can be trained and deployed in modern security operation centers to optimize alert triaging and cyber threat classification. A training dataset of classified records is obtained. Each classified record in the training dataset includes detection characteristics data of a set of machines and threat classification results produced by performing alert triage classification of detection messages associated with the set of machines. An ATC model is trained using the training dataset according to a machine learning technique. The training tunes the ATC model to classify, based on at least the detection characteristics data, a new detection message associated with a machine from the set of machines as a threat or as not a threat.
Owner:RAPID7 INC

Method, apparatus, system, and non-transitory computer readable medium for identifying and prioritizing network security events

PendingUS20260100962A1Computer security arrangementsSecuring communicationSecurity operations centerData set
A server for identifying and prioritizing IT security events associated with a network is caused to receive a dataset representing IT security events specific to one or more resources associated with the network, generate, by defined algorithms, individual scores for the IT security events, correlate each of the individual scores for the IT security events with the one or more resources, aggregate, for a resource of the one or more resources, each of the individual scores correlated with the resource into a security score specific to the resource, determine whether the security score exceeds a defined threshold, and in response to the security score exceeding the defined threshold, generate and transmit a security incident alert specific to the resource to a security operation center. Example servers, systems, apparatuses, methods, and non-transitory computer readable medium for identifying and prioritizing IT security events associated with a network are also disclosed.
Owner:CHARLES SCHWAB & CO INC

Cybersecurity operations center load balancing

PendingUS20260087429A1InstrumentsSecurity operations centerData mining
Disclosed techniques include cybersecurity operations center load balancing. A cybersecurity security operations center (SOC) caseload history is accessed. Triage results from the SOC caseload history are analyzed on a computer platform to produce an analyst threat response profile. The analyst threat response profile is augmented with threat response resolution metrics. The threat response resolution metrics are updated with a subjective rating. The subjective rating is supplied by management, peers, or machine learning. Notification of a new cybersecurity threat is received across a cybersecurity network by the SOC. The new cybersecurity threat is assigned to a specific analyst, based on the augmented analyst threat response profile. The assigning is further based on weighting of threat severity, threat complexity, and analyst availability. An existing SOC caseload is reassigned to increase availability of the specific analyst.
Owner:ARCTIC WOLF NETWORKS INC

Autonomous cybersecurity operations center utilizing micro-model architecture

ActiveUS12634190B1TransmissionElectric digital data processingTicketSecurity operations center
A system and method for improving security operations center (SOC) response to cybersecurity events is presented. The method includes extracting data from a plurality of data sources of a computing environment; receiving a plurality of data guidelines respective of the computing environment; configuring a plurality of micro-models of a SOC system based on: the extracted data and the plurality of data guidelines; receiving a ticket record, the ticket record generated based on an event in the computing environment; processing the ticket record utilizing a portion of the plurality of micro-models; generating a mitigation action based on the processed ticket record; and initiating the mitigation action in the computing environment.
Owner:CONIFERS TECHNOLOGIES INC

Intelligent security operation method and device based on c4isr and electronic equipment

PendingCN122179228ASecuring communicationKnowledge based modelsLinguistic modelSecurity operations center
The application belongs to the technical field of information security, and relates to an intelligent security operation method and device based on C4ISR and electronic equipment, the method comprising: constructing a network security field large language model; embedding the network security field large language model as an intelligent core into an existing security operation center; establishing a multi-agent mapping model based on C4ISR; designing a multi-agent collaborative work architecture based on the multi-agent mapping model; formulating a multi-agent system closed-loop work process; and designing a hierarchical fusion security operation center platform architecture. The risk research and response efficiency is improved, global collaboration and active defense are realized, and asset management and situation awareness capabilities are enhanced.
Owner:SHENZHEN Y& D ELECTRONICS CO LTD

Method and device for detecting and analyzing abnormality in a vehicle

PendingUS20260081949A1Securing communicationSecurity operations centerData mining
A method of detecting and analyzing a vehicle abnormality by a vehicle security operation center includes collecting logs from a vehicle and sorting the collected logs by each type. The method also includes determining whether a frequency of the logs sorted by each type is a threshold value or more and performing a specific analysis on logs determined that a frequency is greater than or equal to the threshold value. The method additionally includes responding to control the vehicle to perform one or more operations based on a result of the specific analysis.
Owner:HYUNDAI MOTOR CO LTD +1

Autonomous cybersecurity operations center utilizing micro-model architecture

ActiveUS20260142866A1Platform integrity maintainanceTransmissionTicketSecurity operations center
A system and method for improving security operations center (SOC) response to cybersecurity events is presented. The method includes extracting data from a plurality of data sources of a computing environment; receiving a plurality of data guidelines respective of the computing environment; configuring a plurality of micro-models of a SOC system based on: the extracted data and the plurality of data guidelines; receiving a ticket record, the ticket record generated based on an event in the computing environment; processing the ticket record utilizing a portion of the plurality of micro-models; generating a mitigation action based on the processed ticket record; and initiating the mitigation action in the computing environment.
Owner:CONIFERS TECHNOLOGIES INC

DNS security operation center insights

PCT designated stageWO2026024337A1Digital data protectionInternal/peripheral component protectionDomain nameSecurity operations center
Various techniques for DNS security operations center insights are disclosed. In some embodiments, a system / process / computer program product for DNS security operations center insights includes collecting Domain Name System (DNS) security associated events; generating a plurality of insights based on the collected DNS security associated events; and performing an action based on one or more of the insights.
Owner:INFOBLOX INC

Security alarm automatic response processing method, device and equipment of enterprise digital system and medium

The invention discloses a security alarm automatic response processing method, device and equipment for an enterprise digital system and a medium, which are applied to a security operation center and relate to the technical field of network security, and the method comprises the following steps: standardizing alarm data collected by a plurality of target data sources related to the enterprise digital system, and adding corresponding context information; generating an alarm relation graph between the alarm information and the alarm object based on the obtained target alarm data, determining first alarm data having a homologous relationship from the alarm relation graph by using a graph clustering algorithm, and determining second alarm data having a logic relationship by using an HDBSCAN clustering algorithm so as to determine a target alarm event; and analyzing the target alarm event based on a machine learning model to obtain an analysis result, and performing alarm processing operation of the target risk level by using the alarm relation graph, the target alarm event, the analysis result and the attack chain information. The automatic response efficiency of the alarm is improved, and real threats are prevented from being submerged.
Owner:HANGZHOU DBAPPSECURITY CO LTD

DNS security operation center insights

PendingUS20260032132A1Securing communicationDomain nameSecurity operations center
Various techniques for DNS security operations center insights are disclosed. In some embodiments, a system / process / computer program product for DNS security operations center insights includes collecting Domain Name System (DNS) security associated events; generating a plurality of insights based on the collected DNS security associated events; and performing an action based on one or more of the insights.
Owner:INFOBLOX INC

System and method for using large language models to respond to information security incidents

An exemplary method for security monitoring and incident response using large language models comprises: receiving input data from elements of Security Operations Center (SOC), generating and sending a query based on the received input data to a Large Language Model (LLM), parsing a response received from the LLM, and performing analysis to determine whether a threat has been identified. In one aspect, the method further comprises: when a threat is identified, collecting artifacts of the threat, and analyzing the threat further with involvement of security professionals, when a threat is not identified, determining whether additional data is needed, and when additional data is needed, determining a type of the additional data, when the type of additional data that is determined, collecting additional information from elements of the SOC, and when additional data is not needed, terminating the incident response.
Owner:AO KASPERSKY LAB