Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

33 results about "Security operations center" patented technology

A security operations center (SOC) is a centralized unit that deals with security issues on an organizational and technical level. A SOC within a building or facility is a central location from where staff supervises the site, using data processing technology. Typically, a SOC is equipped for access monitoring, and controlling of lighting, alarms, and vehicle barriers.

A network security monitoring system to deal with APT attacks

The present invention belongs to the field of network attack detection, and specifically relates to a network security monitoring system for responding to APT attacks. The system comprises an industrial control network gateway security device, an industrial control network management system, and an industrial control network security operations center. The industrial control network gateway security device includes a behavioral data collection module for collecting network traffic and system activity data from various devices, including intrusion detection systems and flow probes, and providing the data to the industrial control network management system. The industrial control network management system includes a data preprocessing module, a subgraph generation module, a behavioral feature extraction module, and a model training and anomaly detection module. The module preprocesses raw data, generates traceability graphs and subgraphs, extracts behavioral features, and establishes a classification model for anomaly detection. The industrial control network security operations center includes a risk warning reporting module that visually reports detected risks to security operations personnel and generates detailed analysis reports.
Owner:TONGJI UNIV

Network threat systematic protection method

PendingCN121966996ASecuring communicationSecurity operations centerData aggregator
The invention discloses a network threat systematic protection method, and belongs to the technical field of network security. According to the method, a unified policy center is constructed, and three layers of security policies of an overlay network, a terminal and an application are defined and issued in a unified manner; network admission control, terminal security management and API risk monitoring systems are deployed to execute strategies respectively; an intelligent linkage mechanism is established, and cross-system automatic co-processing is realized; centralized monitoring, data aggregation and visual analysis are carried out through the unified safety operation center, and support is provided for optimization; and continuously optimizing the strategy and the rule based on the operation data. According to the invention, the problems of isolation, strategy splitting and response lag of a protection system in the prior art are solved, and an active defense system with cooperative linkage and continuous evolution is constructed.
Owner:GUANGZHOU CHANGBENHENG NETWORK TECHNOLOGY CO LTD +1

System and method for aggregating and securing managed detection and response connection interfaces between multiple networked sources

ActiveUS12457223B2Web data indexingSpecial data processing applicationsData streamSecurity operations center
A system and method for a flexible, high-speed Managed Detection and Response platform that ingests, parses, normalizes, monitors, and correlates nearly any log source or security tool output. The MDR comprising of a declarative connector service that tags events with appropriate data source labels to facilitating data isolation, proper handling, and provenance across multiple customers and security products but otherwise aggregate alerts into a single data stream for consumption by the MDR SOC operators. A connector service further provides a programmatic (API-based) means to interchange data securely across environments. Event data is aggregated by the Managed Detection and Response platform that then utilizes enhanced log ingest capabilities to process the data allowing SOC operators to be able to write rules against the alerts.
Owner:QOMPLX INC

DNS security operation center insights

PCT designated stageWO2026024337A9Digital data protectionInternal/peripheral component protectionDomain nameSecurity operations center
Various techniques for DNS security operations center insights are disclosed. In some embodiments, a system / process / computer program product for DNS security operations center insights includes collecting Domain Name System (DNS) security associated events; generating a plurality of insights based on the collected DNS security associated events; and performing an action based on one or more of the insights.
Owner:INFOBLOX INC

Automobile information safety protection method and device based on multi-level protection mechanism, equipment and storage medium

The invention discloses an automobile information safety protection method and device based on a multi-level protection mechanism, equipment and a storage medium, and relates to the technical field of new energy automobiles. At least one of external communication protection configuration, internal communication protection configuration, hardware protection configuration and software protection configuration of a vehicle is detected; and generating a protection detection result, thereby performing real-time monitoring and deep analysis on the network traffic, the host behavior and the vehicle network state, and feeding back the obtained monitoring analysis result to the cloud security operation center, so as to respond to an abnormal event in time, realize comprehensive perception and dynamic evaluation of the vehicle information security state, and improve the safety of the vehicle. Multiple threats such as external attacks, internal tampering, hardware vulnerabilities and software risks are effectively identified, and in combination with cloud collaborative response, early warning is performed on security incidents, so that the adaptive adjustment capability of a protection strategy is remarkably enhanced, the probability of occurrence of security incidents is reduced, and vehicle operation security and user data privacy are guaranteed.
Owner:DONGFENG LIUZHOU MOTOR

Methods and systems for efficient adaptive logging of cyber threat incidents

ActiveUS12603862B2Securing communicationData packCyber threat intelligence
A packet-filtering network appliance such as a threat intelligence gateway (TIG) protects TCP / IP networks from Internet threats by enforcing certain policies on in-transit packets that are crossing network boundaries. The policies are composed of packet filtering rules derived from cyber threat intelligence (CTI). Logs of rule-matching packets and their associated flows are sent to cyberanalysis applications located at security operations centers (SOCs) and operated by cyberanalysts. Some cyber threats / attacks, or incidents, are composed of many different flows occurring at a very high rate, which generates a flood of logs that may overwhelm computer, storage, network, and cyberanalysis resources, thereby compromising cyber defenses. The present disclosure describes incident logging, in which a single incident log efficiently incorporates the logs of the many flows that comprise the incident, thereby potentially reducing resource consumption while improving the informational / cyberanalytical value of the incident log for cyberanalysis when compared to the component flow logs. Incident logging vs. flow logging can be automatically and adaptively switched on or off depending on the combination of resource consumption and informational / cyberanalytical value.
Owner:CENTRIPETAL NETWORKS INC

System and method for dynamic network security risk identification based on multi-source information and ai driving

The application relates to the technical field of network security, and discloses a dynamic network security risk identification system and method based on multi-source intelligence and AI driving, which comprises a dynamic attack graph modeling module, an AI-driven attack simulation engine and a cooperation module.The modeling module fuses multi-source heterogeneous intelligence to construct a network attack graph and calculate node intelligence confidence; the AI engine takes the confidence into a state space, uses a dynamic entropy mechanism to real-time adjust the randomness of reinforcement learning exploration to accurately simulate an attack path; and the cooperation module links external attack surface management and a security operation center to execute closed-loop feedback verification of automatic defense response and path elimination.The application establishes a mapping relationship between intelligence confidence and exploration strategy, effectively solves the problems of uneven multi-source data quality and unknown path missing report, realizes an automatic closed loop from risk perception, simulation deduction to effect verification, and significantly improves risk identification accuracy and response timeliness.
Owner:CSG EHV POWER TRANSMISSION

Remote monitoring of a security operations center (SOC)

ActiveUS12652315B2Security arrangementSecuring communicationSecurity operations centerBusiness enterprise
Systems and methods for remote monitoring of a Security Operations Center (SOC) via a mobile application are provided. According to one embodiment, a management service retrieves information regarding multiple network elements that are associated with an enterprise network and extracts parameters of the monitored network elements from the retrieved information. The management service prioritizes the monitored network elements by determining a severity level associated with security-related issues of the network elements and generates various monitoring views that summarize in real time various categories of potential security-related issues detected by the SOC. Further, the management service assigns a priority to each monitoring view and displays a video on the display device that cycles through monitoring views in accordance with their respective assigned priorities.
Owner:FORTINET INC

Cybersecurity operations center load balancing

ActiveUS12511595B2InstrumentsSecurity operations centerData mining
Disclosed techniques include cybersecurity operations center load balancing. A cybersecurity security operations center (SOC) caseload history is accessed. Triage results from the SOC caseload history are analyzed on a computer platform to produce an analyst threat response profile. The analyst threat response profile is augmented with threat response resolution metrics. The threat response resolution metrics are updated with a subjective rating. The subjective rating is supplied by management, peers, or machine learning. Notification of a new cybersecurity threat is received across a cybersecurity network by the SOC. The new cybersecurity threat is assigned to a specific analyst, based on the augmented analyst threat response profile. The assigning is further based on weighting of threat severity, threat complexity, and analyst availability. An existing SOC caseload is reassigned to increase availability of the specific analyst.
Owner:ARCTIC WOLF NETWORKS INC

Log analysis device, log analysis method, and log analysis program

PendingJP2025152799AFault responseHardware monitoringSecurity operations centerCyber-attack
To provide a log analysis device, method, and program which enhance the accuracy of determination of false positives and enhance the accuracy of analysis of cyber attacks using security event logs in analysis in a Security Operations Center.SOLUTION: A log analyzing device 10 includes a log acquiring unit 101 that acquires a log indicating an abnormality detected by a sensor of an ECU in a vehicle, a vehicle-state-information acquiring unit 102 that acquires vehicle-state information indicating an internal state and an external state of the vehicle, a storage unit 104 for storing a false-positive determination rule for determining that an abnormality indicated by the log is a false-positive that is an abnormality not caused by cyber attacks, and a false positive estimation rule for determining the possibility of false positive, a false positive log determination unit 105 for determining whether a log is a determined false positive log or an estimated false positive log based on the log or vehicle state information, and an output unit 107 for outputting the estimated false positive log together with flag information showing the estimated false positive without outputting the determined false positive log.SELECTED DRAWING: Figure 6
Owner:DENSO CORP

Llm technology with human input reinforcement learning for suggesting the follow up response actions to detections and incidents

PCT designated stageWO2025188629A8Mathematical modelsArtificial lifeSecurity operations centerEngineering
A system and method are provided for providing guidance to SOC professionals regarding follow-up response actions to detection incidents. A machine-learning (ML) model is trained to receive incident data for security incidents / detections. The ML model then classifies the incidents / detections and determines thereby follow-on actions. Using the trained ML model to automatically generate follow-on actions enables the Security Operation Center (SOC) to timely triage and remediate a high volume of security incidents / detections. Reinforcement training data is generated based on user feedback generated when the SOC reviews the generated follow-on actions and then responds to the incident. The reinforcement training data is used to update and improve the ML model, allowing the ML model to adapt to evolving security threats and conform to current best practices.
Owner:CISCO TECHNOLOGY INC

Real-time automated extraction of campaign CTI from threat reports

PendingUS20260149741A1Semantic analysisComputer security arrangementsSecurity operations centerEngineering
A pipeline has been created that leverages artificial intelligence and machine learning to efficiently extract information from CTI reports obtained from various sources and yielding information that assists security analysts / threat teams (e.g., security operations centers (SoCs)) and improving the quality of CTI. The “CTI analysis pipeline” employs generative artificial intelligence (“genAI”) to summarize a collection of CTI threat reports and extract threat-related information including TTPs from the CTI reports. Relationships among the threat reports are determined based on the extracted threat-related information and encoded in a graph structure. Graph embeddings based on the relationships encoded in the graph structure and semantic embeddings from the report summaries are combined and the combined embeddings are clustered. The resulting clusters and trained clustering model can be used in various ways to improve CTI, such as determining malicious campaigns, augmenting existing campaign information, and detecting new IOCs and TTPs for existing campaigns and new campaigns.
Owner:PALO ALTO NETWORKS INC

DNS security operation center insights for mass spreading detection

Various techniques for DNS security operations center insights for mass spreading detection are disclosed. In some embodiments, a system / process / computer program product for DNS security operations center insights for mass spreading detection includes collecting Domain Name System (DNS) security associated events; generating a plurality of insights based on the collected DNS security associated events, wherein at least one of the plurality of insights includes a mass spreading detection insight; and performing an action based on one or more of the insights including the mass spreading detection insight.
Owner:INFOBLOX INC

Real-time security threat detection and dynamic response at edge security operations center in o-ran systems

PCT designated stageWO2026095970A1Security arrangementSecuring communicationAccess networkSecurity operations center
Embodiments disclosed herein provide a method and system for detecting real-time security threats by a security management engine deployed at an edge network entity in an open radio access network (O-RAN) system and implementing dynamic security policy in real-time and isolating services or components at system level. The method includes receiving input data from one or more target network entities by the security management engine deployed at the edge network entity. The security management engine compares one or more parameters of the input data with pre-defined reference parameters to identify anomalies. Based on the comparison, the method includes detecting an anomaly corresponding to at least one target network entity, in real-time by the security management engine. Upon detecting an anomaly, a real-time response may be implemented by applying a dynamic policy on an affected component and isolating the affected component.
Owner:RAKUTEN MOBILE INC +1

Machine learned alert classification system

ActiveUS12615281B2Machine learningSecuring communicationSecurity operations centerEngineering
Disclosed herein are systems, methods, and processes for a machine learned alert triaging classification (ATC) system that uses machine learning techniques to generate an alert triage classification model that can be trained and deployed in modern security operation centers to optimize alert triaging and cyber threat classification. A training dataset of classified records is obtained. Each classified record in the training dataset includes detection characteristics data of a set of machines and threat classification results produced by performing alert triage classification of detection messages associated with the set of machines. An ATC model is trained using the training dataset according to a machine learning technique. The training tunes the ATC model to classify, based on at least the detection characteristics data, a new detection message associated with a machine from the set of machines as a threat or as not a threat.
Owner:RAPID7 INC

Secure operations center monitoring graphical user interface for electronic devices

ActiveCN309683868SData displayData graph
1. The name of the design product: the security operation center monitoring graphical user interface of electronic equipment. 2. The use of the design product: for program running and data display. 3. The design points of the design product: the graphical user interface in the screen. 4. The picture or photo that best indicates the design points: the front view. 5. The use of the graphical user interface: for viewing the current operation security status and intuitively displaying the overall security data. 6. The human-computer interaction mode of the graphical user interface: the front view is the initial interface; when the "view real-time operation situation" button in the upper left corner of the front view is clicked, the interface change state diagram can be entered.
Owner:BEIJING YOUTEJIE INFORMATION TECH

A data management platform for security incidents

This invention is related to a data management platform for security incidents, which may be adopted by large-scale enterprises, government agencies, financial institutions and healthcare providers and may be used in security operations centers to meet the needs of institutions and organizations in cybersecurity, network management and data analytics, characterized in that it comprises a WAF (1) which detects attacks by monitoring web applications and records these attacks with timestamps and types thereof, a SQL database (2) where the data collected by WAF (1) is organized, a data transfer module (3) where data collected by WAF (1) is securely transmitted in real time to SQL database (2) via a data transfer interface where the format and transfer protocols are managed, and a storage module (4) in which the data organized in the SQL database (2) are stored for the analyzing and reporting processes.
Owner:ISTANBUL GELISIM UNIVSI

Method, apparatus, system, and non-transitory computer readable medium for identifying and prioritizing network security events

PendingUS20260100962A1Computer security arrangementsSecuring communicationSecurity operations centerData set
A server for identifying and prioritizing IT security events associated with a network is caused to receive a dataset representing IT security events specific to one or more resources associated with the network, generate, by defined algorithms, individual scores for the IT security events, correlate each of the individual scores for the IT security events with the one or more resources, aggregate, for a resource of the one or more resources, each of the individual scores correlated with the resource into a security score specific to the resource, determine whether the security score exceeds a defined threshold, and in response to the security score exceeding the defined threshold, generate and transmit a security incident alert specific to the resource to a security operation center. Example servers, systems, apparatuses, methods, and non-transitory computer readable medium for identifying and prioritizing IT security events associated with a network are also disclosed.
Owner:CHARLES SCHWAB & CO INC

Cybersecurity operations center load balancing

PendingUS20260087429A1InstrumentsSecurity operations centerData mining
Disclosed techniques include cybersecurity operations center load balancing. A cybersecurity security operations center (SOC) caseload history is accessed. Triage results from the SOC caseload history are analyzed on a computer platform to produce an analyst threat response profile. The analyst threat response profile is augmented with threat response resolution metrics. The threat response resolution metrics are updated with a subjective rating. The subjective rating is supplied by management, peers, or machine learning. Notification of a new cybersecurity threat is received across a cybersecurity network by the SOC. The new cybersecurity threat is assigned to a specific analyst, based on the augmented analyst threat response profile. The assigning is further based on weighting of threat severity, threat complexity, and analyst availability. An existing SOC caseload is reassigned to increase availability of the specific analyst.
Owner:ARCTIC WOLF NETWORKS INC

Autonomous cybersecurity operations center utilizing micro-model architecture

ActiveUS12634190B1TransmissionElectric digital data processingTicketSecurity operations center
A system and method for improving security operations center (SOC) response to cybersecurity events is presented. The method includes extracting data from a plurality of data sources of a computing environment; receiving a plurality of data guidelines respective of the computing environment; configuring a plurality of micro-models of a SOC system based on: the extracted data and the plurality of data guidelines; receiving a ticket record, the ticket record generated based on an event in the computing environment; processing the ticket record utilizing a portion of the plurality of micro-models; generating a mitigation action based on the processed ticket record; and initiating the mitigation action in the computing environment.
Owner:CONIFERS TECHNOLOGIES INC

Safe and efficient label private data collaborative cleaning method

The invention provides a safe and efficient label private data collaborative cleaning method. A system applied by the method comprises a sender and a receiver, the sender and the receiver are both provided with a security operation center, an attack information data set is stored in the security operation center, the attack information data set comprises at least one group of attack information data, and each group of attack information data is composed of data attributes and corresponding attribute tags; the method comprises an off-line process and an on-line process. According to the method, repeated labels and corresponding data items form a one-to-one mapping relation of key values by using relatively small values, so that rapid coding can be carried out in an off-line stage, and the method can be easily adapted to an on-line stage.
Owner:HAINAN UNIV

Method, apparatus, system, and non-transitory computer readable medium for identifying and prioritizing network security events

ActiveUS12526293B2Computer security arrangementsSecuring communicationSecurity operations centerData set
A server for identifying and prioritizing IT security events associated with a network is caused to receive a dataset representing IT security events specific to one or more resources associated with the network, generate, by defined algorithms, individual scores for the IT security events, correlate each of the individual scores for the IT security events with the one or more resources, aggregate, for a resource of the one or more resources, each of the individual scores correlated with the resource into a security score specific to the resource, determine whether the security score exceeds a defined threshold, and in response to the security score exceeding the defined threshold, generate and transmit a security incident alert specific to the resource to a security operation center. Example servers, systems, apparatuses, methods, and non-transitory computer readable medium for identifying and prioritizing IT security events associated with a network are also disclosed.
Owner:CHARLES SCHWAB & CO INC

Intelligent security operation method and device based on c4isr and electronic equipment

PendingCN122179228ASecuring communicationKnowledge based modelsLinguistic modelSecurity operations center
The application belongs to the technical field of information security, and relates to an intelligent security operation method and device based on C4ISR and electronic equipment, the method comprising: constructing a network security field large language model; embedding the network security field large language model as an intelligent core into an existing security operation center; establishing a multi-agent mapping model based on C4ISR; designing a multi-agent collaborative work architecture based on the multi-agent mapping model; formulating a multi-agent system closed-loop work process; and designing a hierarchical fusion security operation center platform architecture. The risk research and response efficiency is improved, global collaboration and active defense are realized, and asset management and situation awareness capabilities are enhanced.
Owner:SHENZHEN Y& D ELECTRONICS CO LTD

Method and device for detecting and analyzing abnormality in a vehicle

PendingUS20260081949A1Securing communicationSecurity operations centerData mining
A method of detecting and analyzing a vehicle abnormality by a vehicle security operation center includes collecting logs from a vehicle and sorting the collected logs by each type. The method also includes determining whether a frequency of the logs sorted by each type is a threshold value or more and performing a specific analysis on logs determined that a frequency is greater than or equal to the threshold value. The method additionally includes responding to control the vehicle to perform one or more operations based on a result of the specific analysis.
Owner:HYUNDAI MOTOR CO LTD +1

Autonomous cybersecurity operations center utilizing micro-model architecture

ActiveUS20260142866A1Platform integrity maintainanceTransmissionTicketSecurity operations center
A system and method for improving security operations center (SOC) response to cybersecurity events is presented. The method includes extracting data from a plurality of data sources of a computing environment; receiving a plurality of data guidelines respective of the computing environment; configuring a plurality of micro-models of a SOC system based on: the extracted data and the plurality of data guidelines; receiving a ticket record, the ticket record generated based on an event in the computing environment; processing the ticket record utilizing a portion of the plurality of micro-models; generating a mitigation action based on the processed ticket record; and initiating the mitigation action in the computing environment.
Owner:CONIFERS TECHNOLOGIES INC

Method, apparatus, system, and non-transitory computer readable medium for detecting anomalous user access behaviors

A server for detecting anomalies associated with users accessing a network is caused to receive a dataset including static data and dynamic data. The static data includes location data of resources associated with the network and user data, and the dynamic data includes user access events. The server is further caused to detect, with a plurality of unsupervised machine learning models, an anomaly associated with a user accessing the network based on the static data and the dynamic data, determine whether the detected anomaly is critical, and in response to determining the detected anomaly is critical, generate and transmit a security alert specific to the detected anomaly to a security operation center. Other example servers, systems, apparatuses, methods, and non-transitory computer readable medium for detecting anomalies associated with users accessing a network are also disclosed.
Owner:CHARLES SCHWAB & CO INC

DNS security operation center insights

PCT designated stageWO2026024337A1Digital data protectionInternal/peripheral component protectionDomain nameSecurity operations center
Various techniques for DNS security operations center insights are disclosed. In some embodiments, a system / process / computer program product for DNS security operations center insights includes collecting Domain Name System (DNS) security associated events; generating a plurality of insights based on the collected DNS security associated events; and performing an action based on one or more of the insights.
Owner:INFOBLOX INC

Security alarm automatic response processing method, device and equipment of enterprise digital system and medium

The invention discloses a security alarm automatic response processing method, device and equipment for an enterprise digital system and a medium, which are applied to a security operation center and relate to the technical field of network security, and the method comprises the following steps: standardizing alarm data collected by a plurality of target data sources related to the enterprise digital system, and adding corresponding context information; generating an alarm relation graph between the alarm information and the alarm object based on the obtained target alarm data, determining first alarm data having a homologous relationship from the alarm relation graph by using a graph clustering algorithm, and determining second alarm data having a logic relationship by using an HDBSCAN clustering algorithm so as to determine a target alarm event; and analyzing the target alarm event based on a machine learning model to obtain an analysis result, and performing alarm processing operation of the target risk level by using the alarm relation graph, the target alarm event, the analysis result and the attack chain information. The automatic response efficiency of the alarm is improved, and real threats are prevented from being submerged.
Owner:HANGZHOU DBAPPSECURITY CO LTD