Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

43 results about "Security software" patented technology

Method and device for constructing network security operating system, electronic equipment and storage medium

ActiveCN121887549AArtificial lifeSecuring communicationOperational systemTrusted computing base
The invention belongs to the field of network security, and relates to a method and a device for constructing a network security operating system, electronic equipment and a storage medium, and the method comprises the following steps: constructing an autonomously controllable improved microkernel infrastructure; based on the microkernel infrastructure, constructing a full-stack layered security control computing architecture base; constructing intelligent agent components, and deploying a multi-intelligent agent collaborative protection component system; integrating trusted computing and an integrity measurement verification system; performing dynamic adaptation and execution of multiple security policies; and a standardized safety evaluation and adaptive optimization closed loop is established. A trusted computing base is cut from a design source, so that the probability of occurrence of high-risk vulnerabilities is reduced; the real-time defense that the threat is changed and the strategy is changed is realized, and the blind area of the static strategy in resisting the unknown threat is made up; the malicious codes can be blocked before running, and the post passive situation that traditional security software only depends on a feature library for searching and killing is broken; and the contradiction between security capability solidification and threat dynamic evolution is fundamentally solved.
Owner:SHENZHEN Y& D ELECTRONICS CO LTD

Systems and Methods for Detecting Malicious Modifications of a Loaded Software Module

PendingUS20260127266A1Platform integrity maintainanceCall stackSecurity software
Kernel-mode security software detects a trigger event indicative of a specific stage in the lifecycle of a target software entity executing in user mode. In response, the security software identifies a target object residing in memory (e.g., loaded library, chunk of code, etc.) according to a current content of the user-mode call stack, and determines whether the target object is malicious. Various methods described herein detect malicious modifications of a loaded module, such as overload, stomping, and unhooking, among others. Other methods described herein detect dynamically swapped libraries and malicious shellcode, among others.
Owner:BITDEFENDER IPR MANAGEMENT

Using software encoded processing to achieve a SIL rating for safety applications executed in the cloud or in non-safety rated servers

ActiveUS12607970B2Programme controlSafety arrangmentsIndustrial securityIndustrial safety system
A cloud-based industrial safety system executes safety applications and interfaces with industrial assets on the plant floor using software encoded processing (SEP). The use of SEP ensures safety reliable execution of safety applications and data communication software by redundantly executing native code, thereby implementing a level of software-based fault detection that is independent of the hardware on which the safety application operates. This allows the cloud-based industrial safety applications to achieve at least SIL3 safety ratings for safety services even though the safety applications are executed using standard COTS hardware that is commonplace in the server market. The use of SEP to reliably execute safety software on the cloud can make possible a wide variety of safety applications that would be difficult to implement using purely localized industrial safety systems.
Owner:ROCKWELL AUTOMATION TECH INC

Trusted security management system graphical user interface for compute board of electronic device

1. Name of the product in this design: Graphical User Interface for a Trusted Security Management System for Computing Boards in Electronic Devices. 2. Purpose of this design: An electronic device. 3. The key design feature of this product lies in the graphical user interface on the screen. 4. The picture or photo that best illustrates the key design points: Design 1 front view. 5. Design 1 is designated as the basic design. 6. Purpose of the graphical user interface: This design is used to configure the trusted security management policy of the computing board hardware and display the status log of policy protection execution. 7. Human-computer interaction method of graphical user interface: After the program runs, the main view of Design 1 appears; click the "Whitelist" button in the middle of the main view of Design 1 to enter the whitelist interface of the computing board dynamic and static measurement security software, i.e., the interface change state diagram 1 of Design 1; click the "Remote Proof" button on the left side of the interface change state diagram 1 to enter the remote proof execution status log interface of the computing board, i.e., the interface change state diagram 2 of Design 1; click the "Critical Process" button on the left side of the interface change state diagram 2 of Design 1 to enter the critical process protection policy configuration interface of the computing board, i.e., the interface change state diagram 3 of Design 1; click the "Log" button in the interface change state diagram 3 of Design 1 to enter the critical process protection status log display interface of the computing board, i.e., the interface change state diagram 4 of Design 1; click the "Critical Directory" button on the left side of the interface change state diagram 4 of Design 1 to enter the critical directory protection policy configuration interface of the computing board, i.e., the interface change state diagram 5 of Design 1. After the program runs, the main view of Design 2 will appear. Click the "Board Middleware" button on the left side of the main view of Design 2 to enter the middleware management interface of the calculation board software, which is the interface change status diagram of Design 2.
Owner:TIANFU JIANGXI LAB

A computer network security software debugging method and system

The application provides a computer network security software debugging method and system. A plurality of test nodes of a source program in target network security software are set, a key test node is located based on an execution state at each test node, and a target search domain when the source program is tested is constructed by program context information of the key test node. A plurality of program slices with abnormalities in the source program are determined based on a static control flow graph and a dynamic control flow graph of program code in the target search domain. Test overhead of each program slice is determined according to test coverage information of each program slice and path complexity when the source program is tested. Constraint levels of each program slice are determined according to all test overhead and membership between each program slice. Each program slice is debugged through the constraint level of each program slice. The above scheme can accurately point to a problem code line in a network security software debugging process based on constraint levels of each program slice.
Owner:CHENZHOU VOCATIONAL & TECH COLLEGE

System and Method for Allowlisting of Devices

During development, a whitelist is automatically created that includes entries for all programs that will run on the target device. Security software is included in the installation package. After the installation package is installed, the operating system runs the system security software and the system security software intercepts attempts to run any program and only allows programs to run that match an entry in the whitelist. In some embodiments, an entitlement file is created (manually, automatically, or a combination of both) and is included in the installation package. In such embodiments, after initialization, the system security software intercepts attempts to access resources of the target device by programs and only allows access to resources that are identified in the entitlement file for that program.
Owner:PC MATIC INC

Malicious code detection method and system based on semantic analysis

The invention provides a malicious code detection method and system based on semantic analysis, and the method comprises the steps: determining a space where a suspicious code is located based on a monitoring behavior record of security software in a terminal, extracting a target code in the space, and reducing a subsequent malicious code detection interval range; based on the semantic feature extraction model and the text semantic classification model, generating a word sequence containing semantic information corresponding to the target code, and correcting the word sequence; analyzing the corrected word sequence based on a deep text classification model to obtain global text semantics of the target code so as to calibrate malicious code snippets in the target code, and performing code change operation on the space based on distribution characteristics of the malicious code snippets to obtain the target code. And meanwhile, global recognition is performed on the codes by utilizing a semantic feature extraction model and a text semantic classification model, efficient and accurate analysis of code semantics is considered, semantic information of the codes is comprehensively extracted, malicious code components are recognized and positioned in massive codes, and the working accuracy and reliability of security software are improved.
Owner:HUIZHIAN INFORMATION TECH CO LTD

Method and system for security risk identification and controlling release management of software application with vulnerable codes

The embodiments herein provide a method and a system for security risk identification and controlling release management of software application. The method provides security risk identification in a software application as well as integrated tools to direct the efforts of developers to build and maintain secure software. The method provides a unique approach of defining a plurality of Service Level Agreement (SLA) to control a release build for a software application by checking vulnerabilities. Furthermore, the method is flexible enough to adapt in most complicated enterprises and different Software Development Life Cycle (SDLC) processes.
Owner:ARMORCODE INC

Portable AVC automatic joint debugging test device and method

The invention provides a portable AVC automatic joint debugging test device and method, and belongs to the technical field of power equipment. The device comprises a communication module, a data acquisition module, a user interface module, an application program module, a communication protocol stack module, a security software module and a data processing library module. The method comprises the following steps: generating a task request, sending the task request to a command theme subscribed by each AVC substation, obtaining real-time data collected by each AVC substation, decrypting and verifying to obtain plaintext data, inputting a dynamic and static curve real-time discrimination model constructed based on a deep reinforcement learning network, outputting a dynamic and static curve discrimination result, and outputting the dynamic and static curve discrimination result. And inputting a PID parameter cost function constructed by a model prediction control algorithm, solving optimized PID parameters of each substation, and issuing the optimized PID parameters to each AVC substation to recollect data until the comprehensive performance grade of each AVC substation is qualified. According to the invention, the blank of the AVC substation joint debugging test device is filled, and the judgment accuracy of the multi-AVC substation joint debugging test result is improved.
Owner:STATE GRID LIAONING ELECTRIC POWER CO LTD

Automated and secure software management process across multiple computer terminals with real-time monitoring and notifications

The present invention relates to a method for managing software on computer terminals (computers, mobile phones, tablets) used by a community within an entity with security policies. Each terminal incorporates a data collection module that monitors user interactions with various applications in real time. The process includes recording usage references, identifying the applications used, and collecting associated data. This data is analyzed to identify applications in real time and detect anomalies compared to normal usage. In the event of abnormal behavior or to optimize software usage, personalized notifications are generated in real time. These notifications can be sent directly to the terminals via email or integrated into the user interface.This process aims for centralized, proactive, and automated governance to strengthen the compliance, security, and efficiency of applications used within an organization. See Figure 1 for an abstract.
Owner:BEAMY

Verifying secure software images using digital certificates

The embodiments relate to improved security in computing devices. In some aspects, the techniques described herein relate to a device including: a secure storage area, the secure storage area including a first public key written during manufacturing of the device; a controller configured to: receive data, the data including a payload, digital certificate, and digital signature, validate the digital certificate using the first public key, extract a second public key from the digital certificate; validate the digital signature using the second public key; and process the payload.
Owner:MICRON TECHNOLOGY INC

Techniques for securing software components through security packages defined in software image recipes

A system and method for software image management. A method includes generating a plurality of software packages including a plurality of units of code, wherein each software package is generated using a respective unit of code of the plurality of units of code, wherein the plurality of software packages includes a security package, wherein the respective unit of code for the security package configures a processing circuitry to perform at least one cybersecurity function when executed by the processing circuitry; and building a software image based on the plurality of software packages by executing a set of instructions of a file, wherein the set of instructions causes the plurality of software packages to be combined in order to build the software image when executed.
Owner:MINIMUS LTD

Attack detection method, apparatus and electronic device

PendingCN122346842ACall stackSecurity software
The application provides an attack detection method and device and electronic equipment, and relates to the technical field of computers. In the method, when it is detected that a target task is executed, the call stack of the target task is acquired first, then it is detected whether the call stack of the target task includes the characteristics of a stack confusion attack, and in the case where the call stack of the target task includes the characteristics of the stack confusion attack, it is determined that the target task is threatened. The technical scheme provided by the application can improve the accuracy of EDR and other security software when detecting attacks.
Owner:HUAWEI TECH CO LTD

Equipment networking behavior management method

The invention belongs to the technical field of network security, and particularly provides an equipment networking behavior management method, which is characterized in that terminal equipment is monitored through a terminal security management platform, the installation and operation states of security software are known, and networking behavior management equipment controls network access limitation of the terminal equipment according to the installation and operation states of the security software. Through the setting, the strong binding of the network access permission and the terminal security state is realized, the management vulnerability depending on the consciousness of employees is eliminated from the technical level, and the security policy is ensured to be executed. And for the non-compliant terminal equipment, only the intranet resources are allowed to be accessed, so that the security risk caused by random access to the Internet is blocked. And when the access is intercepted, a repair guide page is set, so that a user clearly knows a problem source and a solution. And after the terminal equipment completes security repair and updates the security compliance state information, the Internet access behavior management equipment relieves the network access restriction on the terminal equipment.
Owner:CHINA LIFE INSURANCE CO LTD HEBEI BRANCH

Systems and methods for providing end-to-end supply chain security software acquisition in a centralized distribution system

Systems and methods for providing end-to-end chain security software acquisition in a centralized distribution system receive a request to install a software product in a centralized distribution system; verify that the software product has not yet been validated; quarantine the software product in a quarantine zone; validate the software product within the quarantine zone; and distribute the software product to a consumption zone when the software product passes the validation.
Owner:THE BANK OF NEW YORK MELLON

High-security software input and output configuration method based on functional module

The invention discloses a high-security software input and output configuration method based on a functional module, belongs to the technical field of aviation airborne equipment communication software configuration, aims at solving the problems of code redundancy, low development efficiency and poor compatibility and expandability, and comprises the following steps: S1, integrating equipment communication parameters through a three-level hierarchical configuration file; s2, constructing an indexed data dictionary based on the unified configuration file; s3, realizing dynamic construction and analysis of communication data by using the index; the configuration file replaces more than 70% of communication code writing work, the period for adapting to new equipment is shortened to the day level from the week level, duplicate codes are reduced, the number of code lines is reduced, the maintenance labor cost is reduced, when a new protocol (such as CANopen) is expanded through the configuration file, bottom layer codes do not need to be modified, compatibility is improved, and the method is suitable for popularization and application. And communication parameters are visually presented through a configuration file, and the communication fault troubleshooting time is shortened from an hour level to a minute level in combination with an index tracking function of a data dictionary.
Owner:上海柘飞航空科技有限公司

Cross-domain intercom group communication system, method and apparatus, and device and medium

PCT designated stageWO2026138686A1Resource poolGroup communication systems
Provided in the embodiments of the present application are a cross-domain intercom group communication system, method and apparatus, and a device and a medium. In the present application, a first quantum security software development kit sends to a first quantum key system a key application request for the communication of a group, receives first authentication code information and a key identifier that are sent by means of the first quantum key system, and sends group information of the group, the first authentication code information and the key identifier to a second quantum security software development kit; the second quantum security software development kit sends an identity token of the second quantum security software development kit, the group information, the first authentication code information and the key identifier to a second quantum key system; the second quantum key system determines verified authentication code information; and a second intercom terminal establishes communication with a first intercom terminal by means of the verified authentication code information, such that the first intercom terminal and the second intercom terminal can communication with each other even if they are terminals in an intercom group of a cross-domain quantum resource pool.
Owner:CHINA TELECOM QUANTUM INFORMATION TECH GRP CO LTD

Network security software abnormal behavior monitoring method and system

The invention provides a network security software abnormal behavior monitoring method and system. The method comprises the following steps: acquiring process system layer calling data and constructing a calling sequence representing behavior characteristics; discrete call events in the sequence are vectorized and embedded, and a feature space capable of measuring behavior semantics is built; modeling is carried out on the feature space time sequence, a probability transfer model reflecting the dependency relationship between calls is established, and a high-frequency core behavior path and a low-frequency abnormal behavior mode are identified; then, a process behavior topological representation is constructed according to the process behavior topological representation, and a response is triggered when the risk reaches a preset condition through path analysis and risk assessment; and finally, multi-dimensional risk index quantitative evaluation is fused, a behavior credibility security score is generated, and a self-adaptive security policy is executed according to the score to monitor and deal with the abnormal behavior, so that the process abnormal behavior can be accurately identified, self-adaptive security response can be executed, and the network security is guaranteed.
Owner:BEIJING JINXIU YUANFENG TECHNOLOGY CO LTD

Cyber deception automation process

A method, system, and medium for hiding security software on a computing system to limit or prevent cyber attackers and similar malicious actors from identifying, disabling, or otherwise avoiding security software. Embodiments include security software hiding techniques that change the file location of the security software, interrupt the initial phases of an attack, and flag attempts at circumventing the hiding techniques.
Owner:LEGIOX CYBER TECHNOLOGIES INC

Method and device for calling SQLite database by Lisp language based on CAD

PendingCN122044699ADigital data information retrievalExecution paradigmsLispSecurity software
The invention discloses a method and device for calling an SQLite database through a Lisp language based on CAD, and the method comprises the steps: loading a Lisp loader file in a Lisp interpreter environment of a CAD platform, and obtaining a DLL loading function; through a DLL loading function, an SQLite database operation DLL is loaded into a CAD application process space; calling an interface function provided by an SQLite database operation DLL through a Lisp interpreter so as to open or create an SQLite database file; sending an SQL operation command to the SQLite database file through the interface function, and receiving a return result; and closing the SQLite database file through an interface function. According to the method provided by the invention, on the basis of a registration-free loading mechanism of the DLL, direct and efficient calling of the SQLite database by the Lisp language is realized, and the method is simple in deployment, low in permission requirement, not easy to be interfered by security software, high in single machine efficiency and wide in compatibility.
Owner:XIAN MIDLINE SOFTWARE TECH CO LTD

System and Method for Granular Application Signatures

PendingUS20260141055A1Platform integrity maintainanceProgramming languageSecurity software
A system for computer security includes a signature of a signed library embedded in a program along with a set of transformations that were made during compiling and linking of the program. Computer security software periodically runs and opens the program (all programs) and when the program includes transformations, the computer security software rolls back the transformations to create a copy of the program then the computer security software calculates a check value on the copy and if the check value matches the signature, the program is allowed, otherwise the libraries / program has been compromised and the program is blocked and quarantined.
Owner:PC MATIC INC

Password acquisition method based on RISC-V architecture

The invention discloses a password acquisition method based on an RISC-V architecture, and relates to the technical field of information security, and the method comprises the following steps: S1, environment initialization and resource pre-configuration; s2, constructing a lightweight mode switching mechanism; s3, implementing a compatibility adaptation layer; s4, establishing a fault recovery mechanism; and S5, obtaining a complete process of the password. According to the method and the device, switching preparation time consumption is reduced through M mode environment preloading, authentication requests are processed in batches, the number of times of switching from the U mode to the M mode is reduced, state recording and recovery logic are simplified, unnecessary steps are omitted, mode switching time and resource overhead are greatly reduced, performance loss is remarkably reduced, the system response speed is increased, and system compatibility is greatly improved; the dynamic adaptation layer can automatically match mode support conditions of different RISC-V architectures, a pseudo-U mode scheme and degraded operation options cover simplified and old RISC-V systems, and a unified interface is compatible with third-party security software and biological recognition hardware.
Owner:WUHAN COMPUTING ECOLOGY TECH CO LTD

Block chain-driven distributed network trust mechanism security software development method

The invention belongs to the technical field of information technology and network security, and particularly relates to a distributed network trust mechanism security software development method driven by a block chain, which comprises the following steps of: S1, capturing behavior data flow of each node in a target network through a node behavior acquisition module, and storing behavior data into a distributed account book of the block chain; meanwhile, behavior feature vectors are generated based on time sequence characteristics of node behaviors; s2, according to the behavior feature vector, calculating the time change rate of the node behavior and the second-order change rate of the behavior feature vector; according to the method, through combination of dynamic behavior analysis and a multi-layer perceptron neural network classification technology, accurate identification and dynamic adjustment of node trust levels are realized, static features and dynamic fluctuation features in node behaviors are separated through a dynamic behavior modeling algorithm, time-frequency feature extraction is further carried out on the node behaviors through wavelet transform, and the node trust levels are accurately identified and dynamically adjusted. And the accuracy of trust evaluation is enhanced.
Owner:NANTONG MANXIAN INFORMATION TECHNOLOGY CO LTD

Consistency verification system and method for functional security software control

PendingCN121277047AProgramme controlComputer controlSafety indexSecurity software
The invention discloses a consistency checking system controlled by functional safety software. The consistency checking system comprises a vehicle control unit, wherein the vehicle control unit processes a control logic input signal through a common control core and calculates a first safety index value; processing a control logic safety related input signal through a safety monitoring core and calculating a second safety index value, if a difference value between the two is greater than a safety threshold value, judging that the first safety index value is not credible, and carrying out credible state judgment on the second safety index value; the consistency verification module performs consistency verification on signal sources, invalid value processing processes and error processing processes of the control logic input signals and the safety related input signals by adopting an automatic check algorithm; and performing consistency verification on the state jump condition and the safety index value change limit of the pre-processed control logic input signal and the safety related input signal, and if the consistency verification is passed, determining that the second safety index value is in a credible state. According to the invention, the risk of misinformation of faults is reduced, and the reliability of function safety control is improved.
Owner:DONGFENG HONDA AUTOMOBILE CO LTD

Systems and methods for detecting malicious modifications of a loaded software module

PCT designated stageWO2026093572A1Platform integrity maintainanceCall stackSecurity software
Kernel-mode security software detects a trigger event indicative of a specific stage in the lifecycle of a target software entity executing in user mode. In response, the security software identifies a target object residing in memory (e.g., loaded library, chunk of code, etc.) according to a current content of the user-mode call stack, and determines whether the target object is malicious. Various methods described herein detect malicious modifications of a loaded module, such as overload, stomping, and unhooking, among others. Other methods described herein detect dynamically swapped libraries and malicious shellcode, among others.
Owner:BITDEFENDER IPR MANAGEMENT

Secure software life duration timer

ActiveUS12619687B2Program/content distribution protectionSoftware deploymentApplication program softwareUser device
An example embodiment includes an example embodiment includes a method performed by a processor of a user device. The method including receiving, by the processor of the user device, instructions for installing application software on the user device, and installing the application software on the user device based on the instructions. The installation including installing library code of the application software in a section of a memory device of the user device and installing timer code in the section of the memory device along with the library code. The erasure of the timer code from the memory device causes erasure of the library code from the memory device. Decrementing, by the processor of the user device, the timer code when the processor executes the library code, the timer code limiting a life duration of the user device executing the application software.
Owner:INVENSENSE INC

Trusted security protection method and equipment based on network isolation

PendingCN121567449ASecuring communicationCritical information infrastructureSecurity software
The invention relates to the technical field of network isolation security, and provides a credible security protection method and equipment based on network isolation, and the method comprises the steps: setting a security software module between business software deployed in an extranet and a gatekeeper between the extranet and an intranet; before the service software initiates access to the intranet equipment, the security software module and the gatekeeper perform bidirectional security authentication based on the digital certificate, and the identity and integrity of the service software are verified in the authentication process; only after the authentication step is successfully completed, a trusted security data transmission channel is established between the security software module and the gatekeeper; and in the process that the service software performs service interaction with the intranet equipment through the security data transmission channel, the security software module and the gatekeeper cooperatively execute continuous security protection. According to the invention, the security defense line is substantially moved forward and extends to the service software, so that strong identity authentication of the access subject is realized, and the overall security of the key information infrastructure is systematically improved.
Owner:SHANGHAI GIDEKANG TECHNOLOGY CO LTD

Snapshot scoring for intelligent recovery

A method for restoring a data volume, comprising: receiving a request to restore the data volume; identifying a risk map that is associated with the data volume, the risk map including a plurality of entries, each entry mapping a different respective one of a plurality of snapshot identifiers to a respective risk assessment score for a snapshot corresponding to the snapshot identifier, the respective risk assessment score being generated by security software, the respective risk assessment score representing a level of threat or potential harm posed by one or more files in the data volume; identifying a risk policy that corresponds to the data volume; retrieving the risk assessment score threshold from the risk policy; performing a search of the risk map to identify a snapshot whose respective risk assessment score satisfies the risk assessment score threshold; and using the identified snapshot to restore the data volume.
Owner:DELL PROD LP

Control unit having a secure software component

PCT designated stageWO2026078108A1Safety arrangmentsComputer controlSecurity softwareSoftware engineering
The invention relates to a control unit having a secure software component (12a) and a hardware component (14) for carrying out control and / or monitoring functions for security-critical applications in automation technology, wherein the hardware component (14) is designed to output functional and diagnostic information. The hardware component (14) is not secure, in particular is not certified or checked, wherein the secure software component (12a) has a secure interface (16) and secure functional modules (FB-s) in order to communicate with the non-secure hardware component (14) and to read out the functional and diagnostic information, wherein the secure functional modules (FB-s) are designed to check the functional information for errors using the diagnostic information and to output security-related functional information in order to form a security controller (15a) for securely carrying out the control and / or monitoring functions.
Owner:IFM ELECTRONIC GMBH