Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

1248 results about "Security policy" patented technology

Security policy is a definition of what it means to be secure for a system, organization or other entity. For an organization, it addresses the constraints on behavior of its members as well as constraints imposed on adversaries by mechanisms such as doors, locks, keys and walls. For systems, the security policy addresses constraints on functions and flow among them, constraints on access by external systems and adversaries including programs and access to data by people.

Enterprise employee behavior analysis and safety risk early warning monitoring method and system

The invention provides an enterprise employee behavior analysis and safety risk early warning monitoring method and system, and relates to the technical field of enterprise risk management, and the method comprises the steps: collecting employee terminal operation behavior data, building an activity thermal distribution diagram based on office area grid behavior association intensity, and training a behavior evaluation model. And inputting the behavior scoring matrix into a deep neural network to extract target behavior characteristics, calculating an abnormal behavior risk weight coefficient in combination with a department security policy, performing classification and analyzing a risk diffusion probability, and generating a risk situation index to determine an early warning level. Starting a response strategy according to the early warning level, blocking high-risk early warning in real time, tracking associated accounts, establishing a risk association map, identifying potential risk propagation nodes and performing active protection, finally generating an early warning report and feeding back effective protection rules to a behavior baseline model, and realizing continuous optimization of a risk early warning mechanism. And the accuracy and effectiveness of safety risk early warning in the enterprise are improved.
Owner:STATE GRID HEILONGJIANG ELECTRIC POWER COMPANY

Intelligent ERP financial system data security management and authentication method

The invention relates to the technical field of financial data security, and discloses an intelligent ERP financial system data security management and authentication method. The method comprises the following steps: acquiring an original transaction data stream in an ERP system, extracting key financial fields, and dividing the key financial fields into a sensitive data set and a common data set according to a preset rule; a dynamic encryption strategy framework is constructed based on sensitive data set attributes, the framework comprises multiple levels of encryption strength parameters, and the corresponding encryption strength can be automatically matched according to the authentication level of an access request. And monitoring a system data access behavior in real time, collecting feature data, inputting the feature data into the anomaly detection model, and triggering access blocking when an output anomaly access probability exceeds a threshold value. And generating a periodic integrity verification instruction according to the sensitive data updating frequency, performing integrity verification by using a hash chain technology, recording a result and marking a tampering risk level. And based on the association relationship between the tampering risk level and the abnormal access probability, generating an updated security policy and synchronizing the updated security policy to each data access node.
Owner:BEIJING CSSCA TECH CO LTD

Cross-domain computing task processing method, program product, equipment and medium

The invention discloses a cross-domain computing task processing method, a program product, equipment and a medium, and relates to the technical field of cloud computing. The method comprises the following steps: determining a computing node for executing a cross-domain computing task in a cross-domain collaborative scene, and generating an identity certificate bound with the computing node based on a hardware credible state of the node; collecting security policies of a plurality of management domains for conflict detection and decision, and generating a conflict-free session policy; scheduling the cross-domain computing task to a target computing node meeting a preset credible requirement, and issuing a revocable dynamic session token; and recording the operation information of the cross-domain calculation task in the whole life cycle as an audit event, and generating a chained audit log which is linked by the hash value and is digitally signed through a preset verifiable audit interface. By means of the technical scheme, it can be ensured that the whole life cycle of any computing task meets the closed-loop safety requirements of identity credibility, permission controllability, execution propriability and behavior traceability in the complex distributed computing environment.
Owner:JINAN INSPUR DATA TECH CO LTD

Safety control method and system for remote control of Internet of Things

The invention relates to the technical field of management of the Internet of Things, and discloses a security control method and system for remote control of the Internet of Things, and the system comprises a security remote control platform, a zero-trust gateway, an authentication module, a security policy engine, edge proxy equipment and an encryption communication module. And the authentication module is used for performing identity authentication on the equipment and the user. The security policy engine dynamic access control table comprises access rule entries and associated signature information, and is issued to the edge proxy device through the zero-trust gateway. And the edge proxy device stores the dynamic access control table, verifies the signature information based on the platform public key, and performs matching and verification according to the access rule entry when receiving the control instruction. And the encryption communication module is used for performing encryption transmission on the access control table, the control instruction and the execution result. According to the invention, the whole process of remote control of the Internet of Things is dynamic, secure and credible, and the anti-attack capability and operation reliability of the system are effectively improved.
Owner:JINLANCHEN (BEIJING) TECHNOLOGY CO LTD

Graph-based network security event modeling method and system

The invention relates to a graph-based network security event modeling method and system, and the method comprises the steps: obtaining topological data and security policy information of a network where network security equipment is located, and carrying out the hierarchical construction of a knowledge graph, and obtaining a multi-layer security graph; acquiring real-time monitoring data of the network security equipment, and performing graph adversarial learning association with the multilayer security graph to obtain a dynamic evolution graph sequence; obtaining alarm data of the network security device, and performing anomaly detection on the multilayer security map to obtain an anomaly propagation situation; performing security assessment construction on the dynamic evolution diagram sequence and the abnormal propagation situation to obtain an initial security assessment scheme; performing alarm identification and attack link prediction on the alarm data to obtain a link prediction result; and performing evaluation and prediction on the initial security evaluation scheme and the link prediction result to obtain a security situation evaluation strategy. According to the invention, the security condition of the current network can be evaluated more accurately.
Owner:SHENZHEN TRUSTED CLOUD TECH CO LTD

Industrial control system security policy adaptive configuration method and device and readable storage medium

The invention relates to an industrial control system security policy adaptive configuration method and device and a readable storage medium. According to the method, a control instruction stream, a process variable sampling value and link layer message metadata are synchronously collected, an association hypergraph fusing network semantics, control semantics and physical semantics is constructed to represent a system state, and a sampling period is divided into a plurality of time slots with fixed lengths. In each time slot, self-supervised learning is utilized to extract a topology embedded vector group, and a system operation rule is represented. A robustness envelope interval is generated by calculating a statistical distance between a current time slot and a historical baseline, and is used for driving a reinforcement learning model to generate a security policy parameter set. And executing corresponding access control, traffic shaping and integrity verification operations in the next time slot, generating receipt vector feedback model update according to an execution result, outputting a micro-policy patch with a hash signature and a timestamp, and sending the micro-policy patch to the edge security gateway to realize deployment, thereby realizing closed-loop adaptive optimization of the security policy in the dynamic environment.
Owner:SUZHOU IND & IND CO LTD

Identifying unauthorized entities from network traffic

Systems, methods, and devices to detect unauthorized third-party connections within a network infrastructure, such as by analyzing network traffic data using fuzzy matching and machine learning techniques. One aspect includes receiving network traffic data comprising records of communication events involving network identifiers, determining communication relationships between network entities identified by the network identifiers, accessing entity identifiers associated with known third-party systems, and determining associations between the network identifiers and the entity identifiers using a fuzzy matching process. Other aspects include identifying communication relationships involving the third-party systems based on the associations and detecting unregistered or unknown third-party connections within the network infrastructure. Further aspects include normalizing identifiers, computing string similarity metrics, assigning confidence scores, incorporating external data sources, building network association patterns, comparing current patterns to baseline patterns to detect anomalies, and updating security policies or firewall rules in response to detected anomalies. Additional aspects are provided.
Owner:HSBC GRP MANAGEMENT SERVICES LTD

Intelligent safety management and risk prediction method and system based on cloud computing

The invention relates to the technical field of safety management and risk prediction, in particular to an intelligent safety management and risk prediction method and system based on cloud computing. The method comprises the following steps: dynamically accessing multi-source heterogeneous data through a cloud platform, and forming unified event representation through time alignment and credibility labeling; constructing a hierarchical mixed probability safety twin model, updating dynamic parameters by adopting credibility weighted online variational Bayesian, and outputting a state interface by combining structural adaptation, cross-object graph regularization and physical constraint projection; mapping the twinborn state into a causal feature, constructing an intervening causal graph, generating causal embedding by using a credibility weighted attention network, simulating an intervention operation in an embedding space, and quantifying a risk probability; and generating a multi-candidate security policy, evaluating and sorting through a multi-objective utility function, executing an optimal policy, collecting feedback data, and updating the model and the policy. According to the method, credibility regulation and control, probability twinning and causal intervention are fused, and real-time intelligent decision making of an industrial safety scene is supported.
Owner:JIANGXI MILI INTELLECTUAL PROPERTY OPERATION CO LTD

Lightweight AI security policy adaptive deployment method for edge device

The invention relates to the technical field of edge device security policy deployment, in particular to an edge device-oriented lightweight AI security policy adaptive deployment method. The method comprises the following steps: collecting operation state information of edge equipment, and constructing a current multi-dimensional environment vector and a sliding window feature vector; constructing a strategy candidate library, constructing a strategy adaptability scoring function based on the current multi-dimensional environment vector and a real-time perceived network threat event, and scoring and sorting all candidate strategy items to obtain a strategy execution candidate set; and performing scheduling optimization on the strategy execution candidate set by adopting a multi-objective optimization algorithm, and selecting a strategy combination with the highest deployment score as a deployment result. According to the method, a multi-dimensional strategy adaptability scoring function is constructed, candidate strategy items are screened according to current network threat events and system resource conditions, a strategy screening mechanism from fixed template type configuration to resource awareness and attack scene linkage is converted, and the pertinence and accuracy of strategy deployment are improved.
Owner:BEIJING XINJIE TECHNOLOGY CO LTD

Network space security situation awareness detection analysis system and method

The invention discloses a network space security situation awareness detection analysis system and method, and the system comprises a heterogeneous network flow feature deep extraction unit which obtains a flow feature vector through a distributed probe array and an adaptive sampling strategy; the edge computing gateway multi-dimensional threat feature mapping unit realizes feature space mapping through a multi-dimensional feature mapping matrix; the dynamic weight multi-head attention feature fusion unit fuses features by using an optimized multi-head attention mechanism; the time-space sequence security situation evolution modeling unit constructs an evolution model in combination with the time sequence and the fusion features; the security threat risk quantitative evaluation unit carries out risk quantification; and the heterogeneous security policy collaborative response unit generates a response instruction. According to the method, flow collection, feature mapping, fusion, modeling, quantification and response operation are sequentially executed based on all units of the system. According to the method, efficient perception and accurate response of the network space security situation are realized through a multi-unit cooperation and innovation model.
Owner:SOUTHEAST UNIV

Road intelligent maintenance decision-making system based on multi-dimensional evaluation and deep reinforcement learning

The invention relates to the technical field of road maintenance intelligence, and discloses a road intelligent maintenance decision-making system based on multi-dimensional evaluation and deep reinforcement learning, and the system comprises a geographic space data preprocessing module, a fuzzy TOPSI S evaluation module, a context awareness DQN strategy module, a credibility driving recommendation module, and a security strategy library module. The method comprises the following steps: generating a road health degree and a clustering label through multi-source data geographical weighted preprocessing and fuzzy TOPSI S dynamic weight evaluation; a reinforcement learning reward function is configured based on label differentiation, and a strategy space is explored in combination with noise; the confidence is verified through multiple models, a historical security policy is matched, and model optimization is driven through priority sampling injection samples. According to the method, the evaluation precision is improved through entropy weight-clustering dynamic weight, and flexible decision is realized in combination with reinforcement learning; and three-level security verification and closed-loop optimization are constructed to ensure that the risk is controllable, historical experience migration and multi-source data expansion are supported, and the cross-scene adaptive capacity is enhanced.
Owner:LANZHOU JIAOTONG UNIV

Multi-factor dynamic authentication internet of things network security access platform

The invention relates to the technical field of Internet of Things, and discloses a multi-factor dynamic authentication Internet of Things network security access platform, which adopts a multi-factor authentication mechanism, combines biological characteristics, behavior characteristics and environment characteristics of equipment, performs identity verification through biological recognition, equipment fingerprints and behavior analysis, and utilizes a dynamic authentication strategy. Detecting an abnormal IP behavior and triggering a security policy by adopting a dynamic IP binding technology, combining with equipment fingerprint identification and learning and analyzing an equipment network behavior mode; a dynamic key management mechanism is adopted, and keys are automatically generated, distributed and updated according to different devices, application scenes and communication requirements; machine learning and artificial intelligence technologies are utilized to comprehensively analyze historical access data, abnormal behavior modes, environment security states and the like of equipment, and the security risk of equipment access is automatically evaluated if suspicious equipment is detected. The method has the advantage of improving the security of the Internet of Things.
Owner:卞玉捷

Risk monitoring method based on intelligent association and global situation of multi-source data

The invention belongs to the technical field of network security, and particularly relates to an intelligent association and global situation risk monitoring method based on multi-source data, which comprises the following steps: acquiring a multi-source heterogeneous data set; the multi-source heterogeneous data set is preprocessed, and preprocessed multi-source data is obtained; obtaining an attack behavior association graph according to the multi-source data, and performing anomaly detection on the association graph by using a graph neural network to obtain an explicit attack link and a potential attack link; obtaining a network security situation dynamic graph based on the explicit attack link and the potential attack link; and generating a risk assessment report according to the network security situation dynamic graph, triggering a corresponding security policy, and performing risk monitoring according to the security policy. According to the method, the accuracy and response speed of threat detection are remarkably improved, the global network security situation awareness capability is enhanced, and an intelligent solution is provided for security protection in a complex network environment.
Owner:INFORMATION & COMM CO OF STATE GRID SHAANXI ELECTRIC POWER CO LTD

Real-time data stream classification and security policy self-adaption system based on AI model

The invention belongs to the technical field of multi-source heterogeneous data processing and intelligent strategy self-adaption, and discloses a real-time data stream classification and security strategy self-adaption system based on an AI model, which comprises the following steps: acquiring a multi-source heterogeneous data stream, injecting five-dimensional semantic tags, complementing an implicit relationship among the tags through association reasoning, and generating a standardized enhanced data stream; the optimal AI model is matched to execute real-time data flow classification, credibility grading is carried out, and a candidate strategy set is generated through matching; matching an association rule through a rule relation graph, and combining system real-time state mirror image execution strategy influence chain rehearsal to generate a rehearsal verification strategy set; cross-domain transactions are packaged according to cross-domain transaction description specifications, and transaction execution states and physical feedback data are collected in real time through four-stage submission protocol execution; life cycle management is implemented through rule efficiency evaluation, and a rule evolution instruction and sample enhancement data are obtained by combining full-link auditing and are fed back to a preorder link to form a closed loop.
Owner:HENAN HAIRONG SOFTWARE CO LTD

Method and system for automatically executing network security policy based on artificial intelligence large model

The invention provides a network security policy automatic execution method and system based on an artificial intelligence large model, and relates to the technical field of network security, and the method comprises the steps: firstly obtaining a network threat chain data set comprising a threat initiating node, an intermediate propagation node, a target attacked node and propagation path description; calling a pre-trained threat chain analysis large model to carry out hierarchical disassembly and variation trend prediction, outputting a threat chain disassembly map, then extracting a matching strategy gene segment from a preset security strategy gene pool, generating candidate security strategies through model gene recombination and cross-strategy collaborative adaptation, and carrying out threat chain analysis on the candidate security strategies; inputting the candidate strategies, the current network topology and the equipment resource load data into a strategy execution deduction system, outputting an executable security strategy set adaptive to the current network state, finally issuing the executable security strategy set to network security equipment, and collecting execution feedback data for updating the threat chain analysis large model. And automatic, efficient and accurate generation and execution of the network security policy are realized.
Owner:XINYUAN NETWORK TECH CO LTD

Operation and maintenance service automation safety compliance detection system and method

The invention relates to the technical field of operation and maintenance safety compliance, and discloses an operation and maintenance service automation safety compliance detection system and method. The system comprises an operation and maintenance event acquisition unit, a strategy execution unit, a compliance analysis unit, a strategy optimization unit and a violation tracing unit. The operation and maintenance event acquisition unit captures operation and maintenance operation events and execution environment parameters in real time, packages the operation and maintenance operation events and the execution environment parameters into event data packets and transmits the event data packets to the strategy execution unit; the strategy execution unit extracts a reference strategy rule from the security strategy library, performs matching verification on the event and generates a result; the compliance analysis unit analyzes compliance fluctuation characteristics through a multi-dimensional compliance deviation model in combination with historical records; the strategy optimization unit dynamically adjusts the event capture frequency and corrects a strategy matching rule according to the fluctuation characteristics; the violation tracing unit counts the risk cumulant and generates a violation tracing instruction when the risk cumulant exceeds a preset capacity. According to the system, automation and dynamic adjustment of operation and maintenance safety compliance detection are realized, and a risk accumulation process can be effectively tracked.
Owner:HEBEI HUAJIA ELECTRONIC TECHNOLOGY CO LTD

Network threat knowledge automatic extraction method, electronic equipment and storage medium

PendingCN120930756AWeb data indexingSemantic analysisCyber threat intelligenceLinguistic model
The invention discloses a network threat knowledge automatic extraction method, electronic equipment and a storage medium, and the method comprises the following steps executed by a computer hardware system: collecting threat intelligence data related to an APT organization from a multi-source network security text, and processing the threat intelligence data to generate a standardized corpus; using the pre-training sentence vector model to generate semantic embedding for a corpus input text and a manual annotation example library text, and retrieving similar examples to construct an ICL prompt template; inputting a large language model subjected to LoRA fine tuning, and extracting structured triples of multiple types of entities and semantic relationships; generating standardized entity nodes and updated relation information by adopting semantic aggregation; and constructing an APT organization network threat intelligence knowledge graph and outputting a structured file. The method provides key technical support for APT attack tracing, threat situation awareness and automatic security policy generation.
Owner:GUIZHOU UNIV

Fine-grained security policy enforcement for applications

Embodiments generate state elements based on application requests from a client. The state elements may be enqueued in a state queue associated with an application session for an application requests and the application requests may be forwarded to the application. Application responses from the application may be employed to perform further actions, including: generating message elements based on the application responses such that the message elements may be enqueued in a message queue associated in the application session; determining a portion of the state elements in the state queue that may be associated the message elements; updating the portion of the state elements to advance a protocol state based on the message elements such that the application responses may be communicated to the client.
Owner:DELINEA INC

Artificial intelligence assisted password security policy dynamic adaptive adjustment method

The invention relates to the technical field of data processing, in particular to an artificial intelligence-assisted password security policy dynamic adaptive adjustment method, which comprises the following steps of: acquiring login operation data to generate an encryption feature gradient; the aggregation server generates a dynamically updated federal reference model through a double-channel model updating mechanism, wherein a long-term model updating channel is fused with historical parameters to maintain system stability, and a short-term behavior time window channel dynamically adjusts recent gradient weight based on a time decay function. A graph computation engine generates a spatio-temporal composite risk score. And the risk decision engine generates a third-level response instruction. A risk misjudgment event is verified based on a response result, high-value training samples are screened to drive incremental training, space-time sensitive parameters are finely adjusted by a meta-learning optimizer, and noise is injected into a quantum gradient jammer to defend attacks. Optimized parameters are synchronized to a system module, and a closed-loop adaptive system is formed by combining homomorphic encryption transmission, model digital watermarking, quantum source hardware binding and anti-quantum signature.
Owner:CHINA ACADEMY OF INFORMATION & COMM

Intrusion detection method based on cross-domain security management and shared behavior model

The invention relates to an intrusion detection method based on cross-domain security management and a shared behavior model. The method comprises the following steps: acquiring multi-dimensional original data according to a preset cross-domain data acquisition rule and multi-domain node deployment; performing compliance, integrity and format matching degree verification on the original data, shielding sensitive information by using a dynamic desensitization technology based on a verification result, converting a heterogeneous data format, filtering missing field abnormal data, and obtaining compliance data; the method comprises the following steps: extracting a multi-dimensional feature set of user cross-domain access, constructing a shared behavior feature vector through weighted calculation, constructing a reference behavior model library in combination with a cross-domain security policy, and screening out intrusion behaviors and feature deviation data through feature comparison and behavior deviation calculation; according to the method, cross-domain security audit logs are fused for correlation analysis, intrusion behavior types and risk levels are judged by means of a Bayesian network model, differential security response strategies are generated and executed, and cross-domain intrusion detection and protection are achieved.
Owner:SHANGHAI TONTON INFORMATION TECH CO LTD

Dynamic cybersecurity policy management based on contextual adaptive learning

A computerized system for dynamic cybersecurity policy using AI-based contextual adaptive learning includes an AI system that evaluates business contexts, risk tolerance, and productivity impact to generate threat intelligence assessments. The system includes a Contextual Adaptive Learning module that dynamically adjusts cybersecurity policies based on threat assessments to create security workflows. A Cybersecurity Mesh Development module that integrates policies across security frameworks. A Dynamic Scenario Catalog module that updates policy adjustments based on threat intelligence. An Automated Workflow Orchestration module that creates and refines security workflows for optimal efficiency. A Policy Recommendation and Automation module that generates prioritized security recommendations and automates policy changes based on organizational risk profiles and current security controls. This system harmonizes security policies while considering business context, risk, and productivity impacts.
Owner:PURATHEPPARAMBIL SANTHOSH KUNJAPPAN +2

Smart power grid cloud edge collaborative heterogeneous data security access method

The invention provides a smart power grid cloud edge collaborative heterogeneous data security access method, which comprises the following steps: collecting multi-source heterogeneous power equipment data in real time based on a deployed multi-mode sensor network; based on a lightweight federated learning edge inference engine deployed on an edge end network, performing adaptive semantic enhancement preprocessing on the multi-source heterogeneous power equipment data to generate an edge encryption feature tensor; performing three-dimensional credible security authentication and knowledge fusion on the edge encryption feature tensor based on an electric power space-time knowledge graph fusion engine deployed on the cloud side to generate secure and credible electric power data; and performing space-time causal reasoning and twin mirror image comparison on the secure and credible power data based on a federated block chain-driven digital twin decision engine deployed at a cloud end to generate a dynamic security policy map and store the dynamic security policy map. According to the scheme, the data security is enhanced, intelligent analysis and dynamic decision can be performed according to the real-time state of the power grid, and optimal scheduling and stable operation of the power grid are realized.
Owner:浙江浙能数字科技有限公司

Safety management method for financial data synchronization

The invention relates to the technical field of data management, in particular to a safety management method for financial data synchronization, which comprises the following steps: acquiring an original financial data stream, and performing data fragmentation processing on the original financial data stream to obtain fragmented data packets and data fingerprints; performing storage node mapping on the redundant coded data packet according to the storage network to obtain a storage node address chain; and performing abnormal access behavior identification on the storage node address chain according to the security threshold model to obtain a security policy instruction, and deploying the financial scheduling model to a cloud edge collaboration platform to realize security management of financial data synchronization. According to the method, data fragmentation processing, encryption and identity binding are performed on the original financial data, so that the confidentiality of the data can be effectively protected, the data is prevented from being accessed or tampered by an unauthorized third party in a transmission process, and the encrypted data packet ensures secure transmission of the data.
Owner:SHANDONG VOCATIONAL COLLEGE OF ECONOMICS & TRADE +1

Clustering decision-based security baseline setting method, system and device, and medium

The invention relates to the technical field of information security, in particular to a security baseline setting method and system equipment based on clustering decision and a medium, and the method comprises the steps: collecting original data, carrying out the construction of a feature vector through feature conversion, generating a sample, and marking and extracting the sample; constructing a classification model by using manifold learning, inputting the extracted feature vectors into the constructed classification model, optimizing the model through training, and outputting classification labels; processing the decision boundary by using constraint optimization and feature scaling to obtain a standardized feature vector converted by a decision boundary model, grouping based on the standardized feature vector, and extracting a baseline; the security policy is generated through data analysis, and the data is dynamically updated and continuously monitored, so that the unified configuration and centralized management of the security policy are realized, and the policy implementation efficiency and the system expansibility are remarkably improved.
Owner:GUANGXI POWER GRID CORP

Notebook software vulnerability scanning method and system based on security policy

The invention relates to a notebook software vulnerability scanning method based on a security policy. According to the method, firstly, a security policy library of a target notebook is obtained, and the security policy library comprises access control rules, data operation limiting conditions and vulnerability detection reference requirements for different software types; collecting software running data of the target notebook computer, wherein the software running data comprises current running process information, file system operation records, network connection states and software configuration parameters; performing matching analysis on the software operation data and the security policy library to generate a preliminary scanning result; evaluating the risk level of the software vulnerability according to the preliminary scanning result; and finally, based on the risk level and the repair guide terms in the security policy library, generating software vulnerability repair guide information. Therefore, notebook software vulnerabilities can be scanned comprehensively and accurately, and effective repair guidance is provided.
Owner:SHENZHEN ZHUO CHUANG INTELLIGENT TECH CO LTD

Base station equipment management method and system based on big data

The invention belongs to the technical field of base station equipment management, and discloses a base station equipment management method and system based on big data. The method comprises the following steps: firstly, collecting security situation data of a physical layer, a network layer and an application layer, extracting time sequence behavior characteristics, performing cross-layer correlation analysis, and constructing an equipment security credibility dynamic evaluation model; then, identifying vulnerability indexes of control nodes according to the trust attenuation curve, and constructing a cascade risk conduction model in combination with a topological connection relationship; dynamically dividing a security isolation domain based on the model and generating protection parameters and control rules; further, a differentiated security policy is configured, and a cross-domain collaborative response channel is established; and finally, dynamically adjusting the isolation domain boundary and the security policy by monitoring the security event frequency and the interception success rate in real time. According to the invention, the conversion from passive defense to active prediction is realized, and the safety protection capability and operation stability of the base station equipment are improved.
Owner:TIANJIN QIANYU ELECTRONIC TECHNOLOGY CO LTD

Data encryption method for multilevel key stream control in industrial gateway

The invention discloses a data encryption method for multilevel key stream control in an industrial gateway, and particularly relates to the technical field of data encryption and network security. The method comprises the steps of obtaining a session identification code and communication context information; generating a first-level basic key based on the session identification code, and generating a multi-level key stream control matrix in combination with communication context information and a multi-source dynamic random factor; according to the hierarchical relationship of the matrix, key stream sequences of corresponding levels are distributed to data packets of different priorities, and the key stream sequences are switched or combined in real time according to data packet types, transmission paths and security policies in the encryption process, and time fragmentation processing and disturbance coding are executed; the encrypted data packet is sent through a multi-protocol forwarding module of the industrial gateway, and the receiving end carries out decryption by using the key stream control matrix; according to the invention, dynamic generation, hierarchical calling and safe switching of the key stream can be realized, and the data confidentiality, integrity and anti-attack capability of the industrial gateway in a complex network environment are remarkably improved.
Owner:NORTHWESTERN POLYTECHNICAL UNIV

Internal and external network security service passing method and system based on edge computing

The invention discloses an internal and external network security service passing method and system based on edge computing, and belongs to the technical field of network security, and the method comprises the steps: obtaining multi-dimensional attribute information of an edge node, generating a security policy basic data set, generating a traffic feature fingerprint and a self-adaptive environment adaptive fingerprint, and calculating a fusion matching degree; edge security entity nodes are generated in combination with service scene adaptive threshold clustering, and then a security policy meta-model with a security policy blueprint as a core is constructed; analyzing the security policy meta-model through a multi-modal semantic analysis engine, generating a dynamic security enhancement model, and mapping the dynamic security enhancement model to a hierarchical security control model; based on the hierarchical model, outputting edge node internal and external network safety passage configuration and a corresponding safety passage ledger through a scenarized configuration generation algorithm; according to the method, adaptive generation, dynamic optimization and accurate execution of the security policy are realized, and the security, the automation level and the operation and maintenance efficiency of internal and external network passing in the edge computing environment are effectively improved.
Owner:HANGZHOU XUNCHUAN TECHNOLOGY CO LTD

Foundational machine learning model application programming interface (API) security

Various embodiments include a system. The system comprises processing circuitry. The processing circuitry obtains an Application Programming Interface (API) call that is associated with a Large Language Model (LLM). The processing circuitry generates a feature vector that numerically represents data included in the API call associated with the LLM. The processing circuitry provides the feature vector to a security LLM trained to detect security threats to the LLM. The processing circuitry obtains an output from the security LLM that indicates a security threat to the LLM. The processing circuitry determines a security policy based on the security threat. The processing circuitry provides the security policy to a security proxy that screens the API call.
Owner:CEQUENCE SECURITY INC

Construction safety assessment method based on multi-model fusion

The invention relates to the technical field of construction safety assessment, and discloses a construction safety assessment method based on multi-model fusion. The method comprises the following steps: acquiring a multi-source safety monitoring data set of a construction site, wherein the multi-source safety monitoring data set covers image sequence data, sensor time sequence data and operation log text data; performing parallel feature extraction processing on the multi-source data to generate an image feature vector, a sensor feature vector and a text feature vector; calling a multi-model fusion framework to carry out cross-modal fusion processing on the three feature vectors to obtain a fusion security feature set; carrying out security risk assessment analysis based on the fused security feature set, and generating a security risk prediction value and a high-risk region identifier; and finally, generating a security policy adjustment instruction according to the risk prediction value and the high-risk area identifier, and feeding back the security policy adjustment instruction to the field control system to trigger real-time intervention operation. According to the method, a high-risk area can be recognized in time, intervention is triggered, and intelligent support is provided for safety management of a construction site.
Owner:SHENYANG HUIZHUYUN TECH CO LTD