Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

60 results about "Security software" patented technology

Method and device for constructing network security operating system, electronic equipment and storage medium

ActiveCN121887549AArtificial lifeSecuring communicationOperational systemTrusted computing base
The invention belongs to the field of network security, and relates to a method and a device for constructing a network security operating system, electronic equipment and a storage medium, and the method comprises the following steps: constructing an autonomously controllable improved microkernel infrastructure; based on the microkernel infrastructure, constructing a full-stack layered security control computing architecture base; constructing intelligent agent components, and deploying a multi-intelligent agent collaborative protection component system; integrating trusted computing and an integrity measurement verification system; performing dynamic adaptation and execution of multiple security policies; and a standardized safety evaluation and adaptive optimization closed loop is established. A trusted computing base is cut from a design source, so that the probability of occurrence of high-risk vulnerabilities is reduced; the real-time defense that the threat is changed and the strategy is changed is realized, and the blind area of the static strategy in resisting the unknown threat is made up; the malicious codes can be blocked before running, and the post passive situation that traditional security software only depends on a feature library for searching and killing is broken; and the contradiction between security capability solidification and threat dynamic evolution is fundamentally solved.
Owner:SHENZHEN Y& D ELECTRONICS CO LTD

Systems and Methods for Detecting Malicious Modifications of a Loaded Software Module

Kernel-mode security software detects a trigger event indicative of a specific stage in the lifecycle of a target software entity executing in user mode. In response, the security software identifies a target object residing in memory (e.g., loaded library, chunk of code, etc.) according to a current content of the user-mode call stack, and determines whether the target object is malicious. Various methods described herein detect malicious modifications of a loaded module, such as overload, stomping, and unhooking, among others. Other methods described herein detect dynamically swapped libraries and malicious shellcode, among others.
Owner:BITDEFENDER IPR MANAGEMENT

Using software encoded processing to achieve a SIL rating for safety applications executed in the cloud or in non-safety rated servers

ActiveUS12607970B2Programme controlSafety arrangmentsIndustrial securityIndustrial safety system
A cloud-based industrial safety system executes safety applications and interfaces with industrial assets on the plant floor using software encoded processing (SEP). The use of SEP ensures safety reliable execution of safety applications and data communication software by redundantly executing native code, thereby implementing a level of software-based fault detection that is independent of the hardware on which the safety application operates. This allows the cloud-based industrial safety applications to achieve at least SIL3 safety ratings for safety services even though the safety applications are executed using standard COTS hardware that is commonplace in the server market. The use of SEP to reliably execute safety software on the cloud can make possible a wide variety of safety applications that would be difficult to implement using purely localized industrial safety systems.
Owner:ROCKWELL AUTOMATION TECH INC

System and method for real-time detection of code integrity violations

A system and method are provided for real-time detection of code integrity violations by combining behavioral stylometry, biometric fingerprinting, and environmental threat analysis. Baseline data of a user's coding style such as indentation, variable naming, and keystroke patterns are stored and compared to live input to calculate deviation scores. Typing behaviors like dwell time, rhythm, and simulated pressure form a biometric fingerprint, while environmental scans detect suspicious network activity, browser extensions, or virtual machine use. A combined risk score is generated, and automated interventions are triggered when it exceeds a threshold, enabling early detection of unauthorized access, AI-generated code, or compromised environments for secure software development.
Owner:BOYLE DANIEL

Trusted security management system graphical user interface for compute board of electronic device

1. Name of the product in this design: Graphical User Interface for a Trusted Security Management System for Computing Boards in Electronic Devices. 2. Purpose of this design: An electronic device. 3. The key design feature of this product lies in the graphical user interface on the screen. 4. The picture or photo that best illustrates the key design points: Design 1 front view. 5. Design 1 is designated as the basic design. 6. Purpose of the graphical user interface: This design is used to configure the trusted security management policy of the computing board hardware and display the status log of policy protection execution. 7. Human-computer interaction method of graphical user interface: After the program runs, the main view of Design 1 appears; click the "Whitelist" button in the middle of the main view of Design 1 to enter the whitelist interface of the computing board dynamic and static measurement security software, i.e., the interface change state diagram 1 of Design 1; click the "Remote Proof" button on the left side of the interface change state diagram 1 to enter the remote proof execution status log interface of the computing board, i.e., the interface change state diagram 2 of Design 1; click the "Critical Process" button on the left side of the interface change state diagram 2 of Design 1 to enter the critical process protection policy configuration interface of the computing board, i.e., the interface change state diagram 3 of Design 1; click the "Log" button in the interface change state diagram 3 of Design 1 to enter the critical process protection status log display interface of the computing board, i.e., the interface change state diagram 4 of Design 1; click the "Critical Directory" button on the left side of the interface change state diagram 4 of Design 1 to enter the critical directory protection policy configuration interface of the computing board, i.e., the interface change state diagram 5 of Design 1. After the program runs, the main view of Design 2 will appear. Click the "Board Middleware" button on the left side of the main view of Design 2 to enter the middleware management interface of the calculation board software, which is the interface change status diagram of Design 2.
Owner:TIANFU JIANGXI LAB

Information processing system, information processing method, and information processing program

To enable a risk to a target system to be evaluated due to vulnerability of security countermeasure software.SOLUTION: An information processing system 1 comprises a first identification unit 18B, a first calculation unit 18C, a second calculation unit 18D, and an output unit 18E. The first identification unit 18B identifies a menace type which can be addressed by installed software, the installed software being security countermeasure software that has been installed in a target system 30, among the security countermeasure software to which vulnerability has been reported. The first calculation unit 18C calculates a first risk value when addressing menace of the identified menace type by the installed software. The second calculation unit 18D calculates a second risk value when not addressing the menace of the identified menace type by the installed software. The output unit 18E outputs damage possibility information including risk value change information showing a change of the second risk value with respect to the first risk value.SELECTED DRAWING: Figure 2
Owner:KK TOSHIBA

A computer network security software debugging method and system

The application provides a computer network security software debugging method and system. A plurality of test nodes of a source program in target network security software are set, a key test node is located based on an execution state at each test node, and a target search domain when the source program is tested is constructed by program context information of the key test node. A plurality of program slices with abnormalities in the source program are determined based on a static control flow graph and a dynamic control flow graph of program code in the target search domain. Test overhead of each program slice is determined according to test coverage information of each program slice and path complexity when the source program is tested. Constraint levels of each program slice are determined according to all test overhead and membership between each program slice. Each program slice is debugged through the constraint level of each program slice. The above scheme can accurately point to a problem code line in a network security software debugging process based on constraint levels of each program slice.
Owner:CHENZHOU VOCATIONAL & TECH COLLEGE

System and Method for Allowlisting of Devices

During development, a whitelist is automatically created that includes entries for all programs that will run on the target device. Security software is included in the installation package. After the installation package is installed, the operating system runs the system security software and the system security software intercepts attempts to run any program and only allows programs to run that match an entry in the whitelist. In some embodiments, an entitlement file is created (manually, automatically, or a combination of both) and is included in the installation package. In such embodiments, after initialization, the system security software intercepts attempts to access resources of the target device by programs and only allows access to resources that are identified in the entitlement file for that program.
Owner:PC MATIC INC

Malicious code detection method and system based on semantic analysis

The invention provides a malicious code detection method and system based on semantic analysis, and the method comprises the steps: determining a space where a suspicious code is located based on a monitoring behavior record of security software in a terminal, extracting a target code in the space, and reducing a subsequent malicious code detection interval range; based on the semantic feature extraction model and the text semantic classification model, generating a word sequence containing semantic information corresponding to the target code, and correcting the word sequence; analyzing the corrected word sequence based on a deep text classification model to obtain global text semantics of the target code so as to calibrate malicious code snippets in the target code, and performing code change operation on the space based on distribution characteristics of the malicious code snippets to obtain the target code. And meanwhile, global recognition is performed on the codes by utilizing a semantic feature extraction model and a text semantic classification model, efficient and accurate analysis of code semantics is considered, semantic information of the codes is comprehensively extracted, malicious code components are recognized and positioned in massive codes, and the working accuracy and reliability of security software are improved.
Owner:HUIZHIAN INFORMATION TECH CO LTD

Method and system for security risk identification and controlling release management of software application with vulnerable codes

The embodiments herein provide a method and a system for security risk identification and controlling release management of software application. The method provides security risk identification in a software application as well as integrated tools to direct the efforts of developers to build and maintain secure software. The method provides a unique approach of defining a plurality of Service Level Agreement (SLA) to control a release build for a software application by checking vulnerabilities. Furthermore, the method is flexible enough to adapt in most complicated enterprises and different Software Development Life Cycle (SDLC) processes.
Owner:ARMORCODE INC

Portable AVC automatic joint debugging test device and method

The invention provides a portable AVC automatic joint debugging test device and method, and belongs to the technical field of power equipment. The device comprises a communication module, a data acquisition module, a user interface module, an application program module, a communication protocol stack module, a security software module and a data processing library module. The method comprises the following steps: generating a task request, sending the task request to a command theme subscribed by each AVC substation, obtaining real-time data collected by each AVC substation, decrypting and verifying to obtain plaintext data, inputting a dynamic and static curve real-time discrimination model constructed based on a deep reinforcement learning network, outputting a dynamic and static curve discrimination result, and outputting the dynamic and static curve discrimination result. And inputting a PID parameter cost function constructed by a model prediction control algorithm, solving optimized PID parameters of each substation, and issuing the optimized PID parameters to each AVC substation to recollect data until the comprehensive performance grade of each AVC substation is qualified. According to the invention, the blank of the AVC substation joint debugging test device is filled, and the judgment accuracy of the multi-AVC substation joint debugging test result is improved.
Owner:STATE GRID LIAONING ELECTRIC POWER CO LTD

Motor function safety monitoring method and device, electronic equipment and storage medium

The invention provides a motor function safety monitoring method and device, electronic equipment and a storage medium, and relates to the technical field of motors. The method comprises the following steps: executing a first-class interrupt processing flow corresponding to a current first-class interrupt task in a time interval from entering the current first-class interrupt task to entering the next first-class interrupt task of the current time, and executing a second-class interrupt task in response to a trigger command for the second-class interrupt task: activating a safety monitoring task, executing a security monitoring processing flow in the security monitoring task; according to the method, the second-class interruption task is triggered in a software triggering mode, and the safety monitoring task is activated in the second-class interruption task processing, so that the problem that the first-class interruption task is limited by the time of a fixed period is avoided, and the increasing requirement of the complexity of motor function safety software is met.
Owner:WUXI INFIMOTION PROPULSION TECH CO LTD +1

Automated and secure software management process across multiple computer terminals with real-time monitoring and notifications

The present invention relates to a method for managing software on computer terminals (computers, mobile phones, tablets) used by a community within an entity with security policies. Each terminal incorporates a data collection module that monitors user interactions with various applications in real time. The process includes recording usage references, identifying the applications used, and collecting associated data. This data is analyzed to identify applications in real time and detect anomalies compared to normal usage. In the event of abnormal behavior or to optimize software usage, personalized notifications are generated in real time. These notifications can be sent directly to the terminals via email or integrated into the user interface.This process aims for centralized, proactive, and automated governance to strengthen the compliance, security, and efficiency of applications used within an organization. See Figure 1 for an abstract.
Owner:BEAMY

High-security software scheduling method based on functional module

The invention discloses a high-security software scheduling method based on a functional module, and relates to the field of civil aircraft airborne software, and the method comprises the following steps: constructing a three-level scheduling model comprising a sequence, a sequence and scheduling, and realizing fine management of the functional module through a sequence-sequence-scheduling hierarchical structure; a phase-based deterministic scheduling algorithm is adopted to ensure that a functional module is strictly executed in a specified period and phase; and designing high-security characteristics, including static resource verification and fault tolerance, modular execution atomization and determinacy of an execution process. The airborne software scheduling method has the advantages that efficient and flexible task scheduling, static configuration verification and fault tolerance and modular atomization execution are realized by constructing a three-level scheduling model, adopting a phase-based deterministic scheduling algorithm and designing a high-safety characteristic, and the safety, reliability and maintainability of airborne software scheduling are remarkably improved.
Owner:上海柘飞航空科技有限公司

Methods and systems for secure software delivery

Methods, systems, and apparatuses for securely delivering software artifacts. A first computing device may be configured to encrypt one or more software artifacts into an encrypted data file and encrypt a key and a policy file associated with the encrypted data file and send the encrypted data file, key, and policy file to a second computing device. The policy file may comprise policy information for authenticating access to the encrypted data file. The second computing device may use the key and the policy information to access and authenticate a software application of the second computing device. The software application may be used to decrypt the data file and access the one or more software artifacts.
Owner:GUARDANT HEALTH INC

Verifying secure software images using digital certificates

The embodiments relate to improved security in computing devices. In some aspects, the techniques described herein relate to a device including: a secure storage area, the secure storage area including a first public key written during manufacturing of the device; a controller configured to: receive data, the data including a payload, digital certificate, and digital signature, validate the digital certificate using the first public key, extract a second public key from the digital certificate; validate the digital signature using the second public key; and process the payload.
Owner:MICRON TECHNOLOGY INC

Techniques for securing software components through security packages defined in software image recipes

A system and method for software image management. A method includes generating a plurality of software packages including a plurality of units of code, wherein each software package is generated using a respective unit of code of the plurality of units of code, wherein the plurality of software packages includes a security package, wherein the respective unit of code for the security package configures a processing circuitry to perform at least one cybersecurity function when executed by the processing circuitry; and building a software image based on the plurality of software packages by executing a set of instructions of a file, wherein the set of instructions causes the plurality of software packages to be combined in order to build the software image when executed.
Owner:MINIMUS LTD

Device access method, device, computer device, and storage medium

The present application relates to a device access method, a network request access method, a device access device, a network request access device, a computer device, a computer-readable storage medium, and a computer program product, and relates to the field of information security technology. By receiving the hardware feature code of the target device requesting network access and security software information, a random key is generated. If it is determined based on the hardware feature code that the target device belongs to an organizational asset, a random number is generated, and then the control terminal encrypts the received random number according to the random key to obtain first encrypted data. The authentication server encrypts the locally generated random number with the received random key to obtain second encrypted data. If the second encrypted data is the same as the first encrypted data, the security score is determined based on the security software information and the hardware feature code, and the network access of the target device is controlled according to the security score. The use of this method can improve the reliability of controlling the access of external devices to the internal network of the enterprise.
Owner:INDUSTRIAL AND COMMERCIAL BANK OF CHINA

A cross-domain intercom group communication system, method, device, equipment and medium

Embodiments of the present invention provide a cross-domain intercom group communication system, method, apparatus, device, and medium. The present invention uses a first quantum security software development toolkit to send a key application request for group communication to a first quantum key system, receives first authentication code information and a key identifier sent by the first quantum key system, and sends group information, first authentication code information, and key identifier of the group to a second quantum security software development toolkit. The second quantum security software development toolkit sends the identity token, group information, first authentication code information, and key identifier of the second quantum security software development toolkit to the second quantum key system. The second quantum key system determines the verified authentication code information, and the second intercom terminal establishes communication with the first intercom terminal through the verified authentication code information, thereby enabling the first intercom terminal and the second intercom terminal to communicate even if they are terminals of an intercom group in a cross-domain quantum resource pool.
Owner:中电信量子信息科技集团有限公司

Attack detection method, apparatus and electronic device

PendingCN122346842ACall stackSecurity software
The application provides an attack detection method and device and electronic equipment, and relates to the technical field of computers. In the method, when it is detected that a target task is executed, the call stack of the target task is acquired first, then it is detected whether the call stack of the target task includes the characteristics of a stack confusion attack, and in the case where the call stack of the target task includes the characteristics of the stack confusion attack, it is determined that the target task is threatened. The technical scheme provided by the application can improve the accuracy of EDR and other security software when detecting attacks.
Owner:HUAWEI TECH CO LTD

Equipment networking behavior management method

The invention belongs to the technical field of network security, and particularly provides an equipment networking behavior management method, which is characterized in that terminal equipment is monitored through a terminal security management platform, the installation and operation states of security software are known, and networking behavior management equipment controls network access limitation of the terminal equipment according to the installation and operation states of the security software. Through the setting, the strong binding of the network access permission and the terminal security state is realized, the management vulnerability depending on the consciousness of employees is eliminated from the technical level, and the security policy is ensured to be executed. And for the non-compliant terminal equipment, only the intranet resources are allowed to be accessed, so that the security risk caused by random access to the Internet is blocked. And when the access is intercepted, a repair guide page is set, so that a user clearly knows a problem source and a solution. And after the terminal equipment completes security repair and updates the security compliance state information, the Internet access behavior management equipment relieves the network access restriction on the terminal equipment.
Owner:CHINA LIFE INSURANCE CO LTD HEBEI BRANCH

Systems and methods for providing end-to-end supply chain security software acquisition in a centralized distribution system

Systems and methods for providing end-to-end chain security software acquisition in a centralized distribution system receive a request to install a software product in a centralized distribution system; verify that the software product has not yet been validated; quarantine the software product in a quarantine zone; validate the software product within the quarantine zone; and distribute the software product to a consumption zone when the software product passes the validation.
Owner:THE BANK OF NEW YORK MELLON

High-security software input and output configuration method based on functional module

The invention discloses a high-security software input and output configuration method based on a functional module, belongs to the technical field of aviation airborne equipment communication software configuration, aims at solving the problems of code redundancy, low development efficiency and poor compatibility and expandability, and comprises the following steps: S1, integrating equipment communication parameters through a three-level hierarchical configuration file; s2, constructing an indexed data dictionary based on the unified configuration file; s3, realizing dynamic construction and analysis of communication data by using the index; the configuration file replaces more than 70% of communication code writing work, the period for adapting to new equipment is shortened to the day level from the week level, duplicate codes are reduced, the number of code lines is reduced, the maintenance labor cost is reduced, when a new protocol (such as CANopen) is expanded through the configuration file, bottom layer codes do not need to be modified, compatibility is improved, and the method is suitable for popularization and application. And communication parameters are visually presented through a configuration file, and the communication fault troubleshooting time is shortened from an hour level to a minute level in combination with an index tracking function of a data dictionary.
Owner:上海柘飞航空科技有限公司

Cross-domain intercom group communication system, method and apparatus, and device and medium

PCT designated stageWO2026138686A1Resource poolGroup communication systems
Provided in the embodiments of the present application are a cross-domain intercom group communication system, method and apparatus, and a device and a medium. In the present application, a first quantum security software development kit sends to a first quantum key system a key application request for the communication of a group, receives first authentication code information and a key identifier that are sent by means of the first quantum key system, and sends group information of the group, the first authentication code information and the key identifier to a second quantum security software development kit; the second quantum security software development kit sends an identity token of the second quantum security software development kit, the group information, the first authentication code information and the key identifier to a second quantum key system; the second quantum key system determines verified authentication code information; and a second intercom terminal establishes communication with a first intercom terminal by means of the verified authentication code information, such that the first intercom terminal and the second intercom terminal can communication with each other even if they are terminals in an intercom group of a cross-domain quantum resource pool.
Owner:CHINA TELECOM QUANTUM INFORMATION TECH GRP CO LTD

Network security software abnormal behavior monitoring method and system

The invention provides a network security software abnormal behavior monitoring method and system. The method comprises the following steps: acquiring process system layer calling data and constructing a calling sequence representing behavior characteristics; discrete call events in the sequence are vectorized and embedded, and a feature space capable of measuring behavior semantics is built; modeling is carried out on the feature space time sequence, a probability transfer model reflecting the dependency relationship between calls is established, and a high-frequency core behavior path and a low-frequency abnormal behavior mode are identified; then, a process behavior topological representation is constructed according to the process behavior topological representation, and a response is triggered when the risk reaches a preset condition through path analysis and risk assessment; and finally, multi-dimensional risk index quantitative evaluation is fused, a behavior credibility security score is generated, and a self-adaptive security policy is executed according to the score to monitor and deal with the abnormal behavior, so that the process abnormal behavior can be accurately identified, self-adaptive security response can be executed, and the network security is guaranteed.
Owner:BEIJING JINXIU YUANFENG TECHNOLOGY CO LTD

Cyber deception automation process

A method, system, and medium for hiding security software on a computing system to limit or prevent cyber attackers and similar malicious actors from identifying, disabling, or otherwise avoiding security software. Embodiments include security software hiding techniques that change the file location of the security software, interrupt the initial phases of an attack, and flag attempts at circumventing the hiding techniques.
Owner:LEGIOX CYBER TECHNOLOGIES INC

Security software unloading method and device, equipment and storage medium

The invention discloses a security software unloading method, device and equipment and a storage medium, and relates to the technical field of computer security, the method comprises the following steps: before preset security software is unloaded, obtaining a calling function of the preset security software, the calling function representing a function called after the security check of the preset security software is passed; modifying a target jump address of a jump function in the resident memory into a call function, wherein the jump function in the resident memory is used for specifying a target jump address corresponding to each system call address in a system call address set; and unloading the preset security software. Before the security software is uninstalled, the target jump address of the jump function in the resident memory applied in advance is modified into the calling function of the preset security software, so that invalid memory is prevented from being generated, after the security software is uninstalled, the system can access the system function through the target jump address in the system calling address set, and the safety of the system is improved. And the normal operation of the system is ensured.
Owner:SHENZHEN KELIRI TECH CO LTD

Method and device for calling SQLite database by Lisp language based on CAD

The invention discloses a method and device for calling an SQLite database through a Lisp language based on CAD, and the method comprises the steps: loading a Lisp loader file in a Lisp interpreter environment of a CAD platform, and obtaining a DLL loading function; through a DLL loading function, an SQLite database operation DLL is loaded into a CAD application process space; calling an interface function provided by an SQLite database operation DLL through a Lisp interpreter so as to open or create an SQLite database file; sending an SQL operation command to the SQLite database file through the interface function, and receiving a return result; and closing the SQLite database file through an interface function. According to the method provided by the invention, on the basis of a registration-free loading mechanism of the DLL, direct and efficient calling of the SQLite database by the Lisp language is realized, and the method is simple in deployment, low in permission requirement, not easy to be interfered by security software, high in single machine efficiency and wide in compatibility.
Owner:XIAN MIDLINE SOFTWARE TECH CO LTD

Function-level intrinsically secure software development system and compilation and debugging method

The present invention belongs to the field of cyberspace security technology, and relates to a function-level intrinsic security software development system and compilation and debugging method. It is constructed based on a dynamic heterogeneous redundant architecture and includes: variants, which complete the business logic in the software project through the execution of variant executable files, wherein the variant executable files are generated through software project configuration files, and each variant executable file contains at least business code for processing business logic and package code for sending and receiving arbitration information. Each calling function in the business code corresponds to a point to be determined, and the package code uses the package function corresponding to the point to be determined to send and receive arbitration information of the point to be determined; an arbiter, which receives the arbitration request sent by the variant package code and performs arbitration processing on the arbitration request; an I / O agent, which processes the variant input and output operations and feeds back the processing results to the arbiter, which distributes them to the corresponding variant. The present invention reduces the user application threshold, can be expanded, and improves the software security protection capability.
Owner:Chinese People's Liberation Army Cyberspace Force Information Engineering University