Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

299 results about "Security testing" patented technology

Security testing is a process intended to reveal flaws in the security mechanisms of an information system that protect data and maintain functionality as intended. Due to the logical limitations of security testing, passing security testing is not an indication that no flaws exist or that the system adequately satisfies the security requirements.

Power generation side industrial control system network security target building method based on virtual-real combination

The invention discloses a virtual-real combination-based power generation side industrial control system network security target construction method. The method comprises the following steps of: constructing a virtual-real combination target environment consisting of a physical equipment layer and a virtual model layer; the heterogeneous industrial control protocol between the physical equipment layer and the virtual model layer is analyzed, protocol semantic information is extracted, and a bidirectional dynamic mapping rule of a physical equipment state and a virtual model state is generated based on the protocol semantic information; based on a state change event of the physical equipment layer, according to a bidirectional dynamic mapping rule, synchronizing changed equipment state data to the virtual model layer in real time, and simulating protocol behavior logic corresponding to the equipment state data in the virtual model layer according to a security test requirement; and based on the attack instruction or the abnormal state signal generated by the virtual model layer, according to the protocol specification format of the target physical equipment, converting the instruction or the signal into an executable control command, and driving the physical equipment layer to execute an operation corresponding to the control command.
Owner:HUANENG POWER INT INC +1

Cloud security verification method and system, electronic equipment and computer readable storage medium

The invention relates to the technical field of cloud security verification, in particular to a cloud security verification method and system, electronic equipment and a computer readable storage medium. The method comprises the steps of generating and isolating an AKSK which is an access key pair for identity verification, simulating an attack behavior in combination with the AKSK, and performing security capability verification based on the simulated attack behavior. According to the method, the AKSK is generated to simulate the attack in the real cloud environment, it is ensured that the test scene highly restores the real attack path, and the technical problem that the traditional security test mainly depends on static policy analysis (such as IAM policy grammar check) and artificial penetration test and cannot simulate the complete attack path after AKSK leakage in the real attack chain is solved.
Owner:BEIJING ZHIQIAN TECH CO LTD

Automated security testing systems using multi-tiered language models

PendingUS20250335601A1Platform integrity maintainanceLocal languageSecurity testing
Cost-effective cyber security risk countermeasure systems and methods enable LLM-based automated security testing for managed cybersecurity services, without leaking sensitive information about target systems. In embodiments, this is accomplished by utilizing flexible local language models that identify and filter target system specific information when communicating with a public large language model to obtain highly accurate security testing patterns.
Owner:HITACHI LTD

Unauthorized vulnerability detection method, device and equipment and readable storage medium

The invention discloses an unauthorized vulnerability detection method, device and equipment and a readable storage medium, and is applied to the field of security detection, and the method comprises the steps: carrying out the semantic recognition of real business flow data through a large language model, and determining a to-be-detected interface; performing semantic analysis on the parameters of the to-be-detected interface by using a large language model to determine target parameters; extracting a parameter value with an unauthorized vulnerability risk in the target parameter from the historical real service flow data; generating a test effective load of the to-be-detected interface based on the target parameter and the parameter value by utilizing a large language model and a preset rule base; and performing unauthorized vulnerability detection on the to-be-detected interface by using the test payload, and determining a detection result. According to the method, the natural language understanding capability of a large language model is utilized, the limitation of traditional regularization preprocessing and effective load generation is broken through, and the method is adaptive to diversified scenes of a complex system.
Owner:HANGZHOU DBAPPSECURITY CO LTD

Test case sample cutting method, device and system and storage medium

The embodiment of the invention provides a test case sample cutting method, device and system and a storage medium, and relates to the technical field of network security testing. The method comprises the following steps: constructing an industrial control system attack tactical library; wherein the tactical library comprises classified and arranged attack techniques and corresponding security attributes; performing information analysis and semantic analysis on the test case sample to generate structured data of the test case sample and / or function points in the test case sample; and cutting the test case sample according to the security attribute and / or the structured data and / or the function point to obtain a test fragment corresponding to the security attribute and / or the function point. According to the method, classification-based attack techniques and security attributes are cut by constructing a tactical library, key information can be accurately extracted and test intentions can be understood through information analysis and semantic analysis, redundant tests are avoided, cut test fragments can concentrate on specific security attributes or function points, the test coverage range is more accurate, and the test efficiency is improved. And the distributed security test effect is improved.
Owner:STATE GRID SHANDONG ELECTRIC POWER CO +2

Network protocol fuzz testing method based on strategy gradient reinforcement learning

The invention provides a network protocol fuzz testing method based on strategy gradient reinforcement learning, and relates to the technical field of fuzz testing, and the method comprises the steps: building a test corpus through obtaining a to-be-tested protocol data packet format; establishing an action space containing a mutation operation set and a state space of a benchmark test data packet feature vector; determining a reward value based on the test result; calculating a strategy gradient by using a reward value, and updating strategy network parameters in combination with an adaptive learning rate; and performing fuzzy testing by using the trained model. According to the invention, the test efficiency is improved, the variation strategy selection is optimized, and the effectiveness of the network protocol security test is enhanced.
Owner:ZHEJIANG SHUXIN NETWORK CO LTD

Implicit gradient optimization-based large language model jailbreak attack resisting method

The invention discloses an implicit gradient optimization-based large language model prison break attack resisting method, which is characterized in that continuous gradient optimization on resistance tokens is realized through a Gumbel-Softmax technology, calculation cost is reduced in combination with a two-stage proxy model screening mechanism, and semantic concealment is kept by adopting a dynamic regularization strategy. The system comprises a gradient optimization module, an agent screening module and a migration enhancement module, and can effectively improve the attack success rate and the cross-model migration capability of resistance prompts. The technical problems that a traditional attack resisting method is low in efficiency and poor in concealment are solved, the attack cost is reduced while the large model attack success rate is increased, the API calling frequency is effectively reduced, and the method is suitable for the field of large language model security testing.
Owner:ZHEJIANG UNIV +1

Method and system for automatically detecting network application vulnerabilities based on large language model

The invention discloses a network application vulnerability automatic detection method and system based on a large language model, and solves the problems of low vulnerability detection efficiency and low accuracy in the prior art. The method comprises the following steps of: S1, searching a path of an application programming interface (API) (Application Program Interface); s2, a big language model vulnerability analysis step; s3, a step of generating a script of a vulnerability PoC (Proof Of Concept: Conceptual Verification); s4, an IDOR (Insecure Direct Object Reference) vulnerability crawler identification step is carried out, and the step S4 is carried out according to the vulnerability crawler identification step and the step S4, the step S4 is carried out according to the vulnerability crawler identification step, and the step S4 is carried out according to the vulnerability crawler identification step. S5, a vulnerability verification step; and S6, a report generation step. According to the method and the system, the whole process from path searching to vulnerability hypothesis generation to automatic vulnerability verification is realized through driving the synergistic effect of multiple modules, the targets of zero false alarm and near-zero manual confirmation are achieved, the efficiency and the accuracy of network application security testing are greatly improved, and powerful support is provided for network security protection.
Owner:ENTROPY (BEIJING) NETWORK TECHNOLOGY CO LTD

Dynamic fuzz testing and vulnerability detection method oriented to API (Application Program Interface)

The invention discloses an API-oriented dynamic fuzz testing and vulnerability detection method, and belongs to the technical field of software security testing. The method comprises the following steps: extracting a dependency relationship, an input parameter, an output response and context state data of API calling, generating an initial API dependency graph, dynamically updating by capturing API state change in real time, forming an API state graph, and executing boundary-oriented variation based on parameter constraint characteristics, so as to obtain an API state graph; generating a variation test parameter, calling an API (Application Program Interface) of the variation test parameter to monitor a process memory behavior and response metadata, and generating a multi-dimensional abnormal signal; and performing mode matching on the abnormal signal and the vulnerability feature knowledge base, outputting a vulnerability type label and generating a path tracing report. According to the method, a context state sensing dynamic graph modeling technology is adopted, and a boundary-oriented intelligent variation strategy and multi-source abnormal behavior collaborative analysis are combined, so that precise vulnerability triggering, intelligent vulnerability judgment and complex scene coverage can be realized.
Owner:GUANGZHOU DAPU INFORMATION TECHNOLOGY CO LTD

System and method of anomaly detection with configuration-related activity profiles

An anomaly detection system uses configuration-related activity profiles, generated in course of threat samples analysis in a secure testing environment, consisting of features of system events and system configurations of endpoints and shared network assets. Backup archives and activity monitors are used to collect system events and system configurations from corporate networks to analyze them with threat pattern databases including configuration-related activity profiles.
Owner:ACRONIS INT

Large model output content security test method and device

The invention relates to the field of large model security testing, and particularly provides a large model output content security testing method and device, and the method comprises the following steps: S1, preparing and managing a test set, a sensitive word library and a regular expression which are required by testing; s2, reading a test set, and obtaining a large model output result according to the test set and the large model interface information; s3, judging whether the output content of the large model is safe or not according to the sensitive lexicon and the regular expression; s4, extracting semantic risk features according to the output content of the large model by using the large model and the oriented Prompt, and automatically storing the semantic risk features after confidence verification; and S5, storing the information result of each request in a file. Compared with the prior art, the test time can be shortened, and the evaluation efficiency can be improved; and the security of the output content of the large model can be effectively evaluated by using a method for dynamically constructing the sensitive word bank by using the output result of the large model.
Owner:INSPUR QILU SOFTWARE IND

Large language model security test method based on evolutionary dynamic adversarial attack

The invention discloses a large language model security testing method based on evolutionary dynamic adversarial attacks, and relates to the technical field of security testing. Comprising the following steps: 1, creating a dynamic attack generation engine, constructing an adversarial evolution architecture by utilizing the dynamic attack generation engine, and generating a test sample based on the adversarial evolution architecture for a large language model security test; the method comprises the following steps: 1, establishing a large-scale language model, 2, calculating investigation parameters of harmlessness, honesty and helpfulness based on a Constancy AI principle, calculating a security alignment gap index SAGI by using the investigation parameters, and intelligently judging a value drift condition of the large-scale language model according to the security alignment gap index SAGI, 3, establishing a multi-modal joint defense engine, and carrying out intelligent judgment on the value drift condition of the large-scale language model according to the value drift condition of the large-scale language model. Steganalysis, syntax tree analysis and audio anomaly detection functions are integrated, and all-around threat detection coverage of texts, codes, images and voices is carried out on a detected large language model.
Owner:INSPUR QILU SOFTWARE IND

Security test method based on concept decomposition and recombination

The invention discloses a security test method based on concept decomposition and recombination, which comprises the following steps of: extracting a malicious intention from an original prompt containing malicious information, and converting the malicious intention into semantic representation of a structured text and a behavior; decomposing the structured text and behavior into a plurality of sub-concepts; screening the sub-concepts, and recombining the sub-concepts into an optimal subset; generating a jail break prompt based on the optimal subset; and inputting the jail break prompt into the target model to attack the target model, and outputting an attacked text by the target model. According to the method disclosed by the invention, on the basis of the generated harmful text, quantitative evaluation is performed on the harmfulness of the generated text from multiple dimensions, and potential risks brought by different attack methods are effectively captured, so that a more comprehensive harmfulness evaluation system is provided.
Owner:UNIV OF CHINESE ACAD OF SCI

Construction method and device for dynamic attack and defense test environment of industrial control system

The invention relates to the technical field of industrial control system security testing, and provides a construction method and device for a dynamic attack and defense testing environment of an industrial control system. The method comprises the following steps: realizing virtualization operation and behavior modeling of industrial control firmware through a hardware system simulation technology based on logic self-learning; constructing a meta-aggregation data resource pool to realize intelligent scheduling and automatic deployment of industrial control component resources; when it is detected that the behavior of the industrial equipment is abnormal, deviation behavior data are complemented based on a causal relationship reasoning mechanism, and a simulation model is driven to be adjusted; constructing a digital-analog fusion model supporting space-time driving and data synchronization, and realizing data consistency and linkage between a virtual environment and a real environment; an AI agent mechanism is introduced, an attack path is automatically deduced, a defense strategy is optimized, and intelligent evaluation of a drilling process is completed; attack protection scene configuration and control are carried out through an interactive user interface, and simulation and verification operations in a complex dynamic attack and defense environment are realized.
Owner:SHANDONG COMP SCI CENTNAT SUPERCOMP CENT IN JINAN +1

Automobile part data life cycle safety test system

The invention discloses an automobile part data life cycle safety test system, and relates to the technical field of automobile part data safety. Comprising a data classification and label module, a storage security test module, a transmission security test module, a use and destruction security module, a compliance and risk assessment module, a full-link linkage test engine, a digital twin drive module and an adaptive test process engine. The method has the advantages that data classification, storage, transmission, use and destruction links are dynamically connected in series by a directed acyclic graph through an event-driven workflow orchestrator of a full-link linkage test engine, and fault injection and risk evolution deduction are executed; a three-dimensional twin space link risk propagation path comprising a physical entity model and a data flow topology is constructed by means of a digital twin driving module, full-link detection of cross-link vulnerabilities such as'mismatching of classification labels and encryption strategies' 'permission combination attack ''and the like is realized, and the systematic risk omission ratio is reduced.
Owner:NAT IND INFORMATION SECURITY DEV RES CENT

Computer performance security test method and system

The invention relates to the technical field of computer system performance and security testing, in particular to a computer performance security testing method and system. The method specifically comprises the steps that performance indexes, behavior characteristics and security event data of a target system are obtained in real time and subjected to standardization processing, clustering modeling is conducted on the behavior characteristics subjected to dimension reduction through a Gaussian mixture model so as to establish a normal behavior pattern cluster, and time sequence analysis is conducted on a behavior sequence in combination with a hidden Markov model so as to recognize a system state transition path; adopting a weighted combination strategy to mix and inject a normal load and an aggressive load, and adjusting an abnormal behavior chain through a disturbance function; constructing directed weighted association between the abnormal event and the performance index based on an event-driven causal performance diagram, quantifying a system risk index and triggering an alarm; outputting performance bottlenecks, security vulnerabilities and optimization suggestions, and updating the knowledge base to optimize subsequent models. According to the invention, deep coupling of performance and safety testing, intelligent scheduling of dynamic loads and interpretable positioning of risk paths are realized.
Owner:NANCHANG CAMPUS OF EAST CHINA UNIV OF TECH

Domain name security test method and device, computer equipment, readable storage medium and program product

The invention relates to a domain name security test method and device, computer equipment, a computer readable storage medium and a computer program product. The method comprises the steps of obtaining a domain name information set of a to-be-checked object; analyzing each piece of domain name information in the domain name information set to obtain a candidate address set, and determining unanalyzed domain names; performing port detection on each address identifier in the candidate address set to obtain a port detection result; according to a port detection result, screening a target address port pair, and determining whether the target address port pair has a reverse proxy attribute; according to the access priority, an access request containing an unresolved domain name is sent to each target address port pair in sequence, and the target address port pair with the reverse proxy attribute has a higher access priority; if effective response information from the target address port pair is received, hidden domain name risk information is obtained according to the unresolved domain name and the target address port pair; the hidden domain name risk information is used for domain name security repair. By adopting the method, the comprehensiveness of network security protection can be improved.
Owner:CHINA TELECOM CLOUD TECH CO LTD

Information security testing and evidence obtaining platform

The invention relates to the technical field of information security, and discloses an information security testing and evidence obtaining platform, which comprises a graphical user interface module for acquiring project information, project types, equipment information and task information, and storing the project information in a relational database; and encrypting and storing the equipment information. And the protocol simulation module integrates SSH, HTTP and MySQL protocol client libraries, realizes remote equipment login, dynamically loads plug-in configuration and executes a multi-dimensional evaluation algorithm, such as regular matching, keyword scanning and configuration priority analysis. A standard rule base is arranged in the compliance rule judgment module, a quantitative evaluation result is generated through Boolean operation, and an SM2 signature engine is integrated for data signature and integrity verification. The abstract is recalculated through the public key data packet and the signature value is compared, so that the data integrity is ensured. According to the invention, the accuracy and pertinence of equipment safety assessment are ensured.
Owner:CHENGDU CHUANGXIN HUATONG INFORMATION TECH CO LTD

5G RedCap application layer security test method, system and device for power business and medium

The invention relates to the technical field of 5G communication security, and discloses a 5G RedCap application layer security test method, system, device and medium for power business, comprising: constructing a power business test scene library, setting a test case for each scene, performing power business communication environment simulation, and in the application layer communication process of a terminal and a master station, establishing a test case for each scene; multiple types of security attacks are dynamically injected to obtain a detection result of the security event; and constructing a multi-dimensional safety evaluation index system, carrying out quantitative scoring and grade evaluation on the application layer safety performance of the 5G RedCap terminal in the power business scene, and generating a test report. According to the method, the test efficiency and consistency are greatly improved, a quantitative security assessment result is provided, the expandability is good, the power business protocol, the business logic and the security risk characteristics are deeply fused, and a business semantic driven security test system is constructed.
Owner:GUIZHOU POWER GRID CO LTD

Security compatibility testing and configuration platform

A novel security testing compatibility and configuration platform that utilizes a virtual emulation on a cloud-based service to assess the functionality of a device after implementing secure configurations. The disclosed platform provides a computer-implemented method for security testing compatibility and configuration comprising (1) using a virtual emulation to capture images of a connected device; (2) building a virtual machine based on the images; (3) applying secure configurations to the virtual machine; (4) executing functions and commands on the virtual machine using AI; (5) creating a report of the results; and (6) applying secure configurations to the connected device.
Owner:CYDEPLOY INC

Test case level-to-level management system

According to the test case level-to-level management system provided by the invention, a dynamic perception-intelligent decision-accurate execution closed-loop system is constructed through cooperative operation of the intelligent arrangement center module, the multi-modal test fusion module and the heterogeneous execution environment adaptation module. Real-time dynamic allocation of test resources is realized based on a bidirectional sensing mechanism, and the resource utilization rate is improved; a data feedback channel of five-dimensional linkage of interface testing, function testing, UI testing, performance testing and safety testing is established through a multi-modal testing fusion module, and cross-modal conversion and multiplexing are carried out on key testing elements such as boundary value cases and safety injection points, so that the coverage rate of a testing scene is increased, and the defect escape rate is reduced; the heterogeneous execution environment adaptation module realizes automatic identification and accurate matching of a virtual machine, a container and a physical machine environment based on a feature fingerprint database, manual configuration errors are eliminated, environment adaptation time consumption is reduced, the test period is greatly shortened, and the defect positioning efficiency is greatly improved.
Owner:HUANENG INFORMATION TECH CO LTD +1

5G security demand extraction and assertion generation technology based on LLM and RAG

The invention relates to a 5G security demand extraction and assertion generation technology based on LLM and RAG, and the technology comprises the following steps: 1, a standard document preprocessing module, splitting a 3GPP standard document according to a security process hierarchy, mapping the 3GPP standard document to a corresponding label, and solving a knowledge fragmentation problem; the RAG knowledge base construction module analyzes document slices by using an RAGF low tool, divides the document slices into text blocks, stores the text blocks into a database through vectorization of an embedded model, and realizes efficient retrieval by adopting hierarchical indexing; 3, an LLM semantic understanding and assertion generation module, which is used for converting a natural language demand into a logic expression based on a DeepSeek model in combination with a cue word framework, a knowledge base and a signaling alphabet; and the assertion post-processing module is used for performing grammar check, standard conformity verification, simplification and logic conflict detection on the LTL assertion. According to the technology, automatic extraction of security requirements and assertion generation are realized, efficiency and accuracy are improved, security requirements in multiple aspects are covered, and a reliable scheme is provided for 5G terminal protocol security testing.
Owner:BEIHANG UNIV

Deep learning framework fuzzy testing method based on large model cue word optimization

The invention relates to the cross technical field of artificial intelligence and software security testing, in particular to a deep learning framework fuzz testing method based on large model cue word optimization, which is used for improving vulnerability mining efficiency and testing intelligence level of fuzz testing on a deep learning framework. According to the method, the advantages of a large language model in the aspects of code understanding and generation are fully utilized, and efficient vulnerability detection of a deep learning framework is realized by introducing a cue word adaptive optimization and variation mechanism. The method mainly comprises the following steps: (1) providing a deep learning framework API classification method and a cue word routing mechanism; (2) proposing a large model cue word adaptive optimization mechanism; and (3) proposing a deep learning framework fuzzy test variation strategy and a dynamic selection mechanism. According to the method, the automation and vulnerability discovery capability of fuzzy testing can be remarkably improved while the generation quality is ensured, and the method has relatively high universality and application value.
Owner:HUNAN UNIV

Intelligent networked automobile data and information security evaluation method and system

The invention relates to the technical field of vehicle-mounted network security, in particular to an intelligent networked automobile data and information security evaluation method and system. The method comprises the following steps: acquiring safety test data of the intelligent networked automobile, wherein the data at least comprises wireless communication safety data, vehicle-mounted network safety data, vehicle-mounted application software safety data and information interaction safety data; analyzing the safety test data by adopting an intelligent network connection automobile safety evaluation model, and identifying potential safety risk points; and according to the identified security risk point, generating a security risk assessment report including a risk level, a risk type and a security protection suggestion. According to the method, a static test environment and a dynamic test environment are combined, an evaluation model is constructed based on industrial standard specifications and historical event data, a multi-level security evaluation architecture is supported, security vulnerability automatic identification and risk level automatic evaluation are realized, closed-loop management is formed through repair scheme formulation and verification, and the security evaluation efficiency is improved. And the data and information security assurance level of the intelligent networked automobile is effectively improved.
Owner:CHINA TRAMCAR UNITED XINAN TECH CO LTD +1

Method for Secure Access to Digital Data

The invention relates to a method for secure access to digital data, said digital data being encrypted with a given user's public encryption key and stored on a server. The method comprises the following steps:A. receiving at said server a request from said user to access said digital data;B. transmitting, via said server, via a secure communication interface, a request to a secure user device to release a password stored on said user device;C. obtaining said password via said secure communication interface, from said user device in response to a validated security test issued by said user device to a user; andD. retrieving, via said server, the user's encrypted private key, said user's private key being encrypted with said password, and decrypting said user's encrypted private key with said password to obtain that user's private key, and decrypting said encrypted digital data with said user's private key, and presenting said digital data to said user.Another method is provided for new users who do not yet have encryption keys, where the sender temporarily encrypts the digital data and, upon user enrollment, the server re-encrypts the data to the user's public encryption key before proceeding with the server-assisted decryption process.
Owner:MAILSPEC LLC

Software development-oriented security processing method and device, equipment and medium

The invention relates to the technical field of data security, can be applied to business scenes of financial science and technology, medical health and the like, and discloses a security processing method, device and equipment oriented to software development and a medium. Obtaining an architecture design document to identify potential safety hazards and generate design improvement suggestions; generating a code based on the business logic description and the design improvement suggestion, and completing security detection and repair to obtain a processed code and a code repair record; performing security test on the processed code and recording a test result; collecting data of exception identification, hidden danger identification, code detection and repair and security test to update the security knowledge base; and generating a security analysis report based on the demand exception list, the design improvement suggestion, the code repair record and the test result. According to the invention, through a security identification and restoration process from demand to test, early discovery of security problems, linkage processing and knowledge self-updating are realized.
Owner:PING AN TECH (SHENZHEN) CO LTD

Multi-agent driven safety alarm log simulation generation method

The invention discloses a multi-agent-driven security alarm log simulation generation method, and relates to the technical field of network security, and the method comprises the following steps: S1, obtaining a sample log; s2, on the basis of the sample log, obtaining and defining an overall feature as Ft, a session feature as Fs, a field feature as Fc, an overall rule as Rt, a session rule as Rs and a field rule as Rc; s3, Ft, Fs, Fc, Rt, Rs and Rc are input into the large language model, logs are generated, and the generated logs are classified into overall logs, session logs and field logs; s4-S6, performing outer-layer circulation, middle-layer circulation and inner-layer circulation on the basis of the generated overall log, session log and field log, so as to obtain a final simulation security alarm log set; and S7, performing quality evaluation on the generated simulation security alarm log. According to the method, the security simulation logs meeting the requirements are generated through various agents, and the method is very valuable in scenes such as security testing, security simulation and application security testing.
Owner:BANK OF SHANGHAI

Large language model (LLM) supply chain security

Disclosed are various approaches for large language model (LLM) supply chain security. In one example, an LLM-extended software bill of materials can be extended to provide LLM specific supply chain information for an LLM application that communicates with an LLM service. The LLM-extended software bill of materials can be attached to the LLM application. An LLM specific security test can be performed on the LLM application. A signed LLM security test attestation can be attached to the LLM-extended software bill of materials based on completion of the automated LLM security test. The LLM application or the LLM-extended software bill of materials can be published or transmitted to a predetermined network endpoint.
Owner:AMERICAN EXPRESS TRAVEL RELATED SERVICES CO INC

Security test system

To grasp appropriate operation procedures of a Web site including operation with sequentiality and to efficiently / effectively perform automatic patrol.SOLUTION: A security test system 1 examining whether or not there is security vulnerability in a Web application acquires and analyzes a Web page to be patrolled in an object Web site 3, sets to prompt information related to a content of the acquired Web page, and inputs it to a LLM 4, creates operation procedure information on the Web page, simulates operation regarding the Web page according to the operation procedure information, acquires an URL related to a link in the Web page, and registers it to a page list 14 to be patrolled.SELECTED DRAWING: Figure 1
Owner:UB SECURE CO LTD

Security test system and method for electric power information system

The invention discloses an electric power information system safety test system and method, and the system comprises a test management scheduling platform, a multi-level test execution engine, a real-time lossless collection and monitoring module, an intelligent analysis and decision engine, a digital twin simulation test platform, and a system self-protection and toughness evaluation module. According to the security test system and method for the electric power information system, all-around and deep security coverage of the electric power information system is realized, the breadth and depth of vulnerability discovery are remarkably improved, meanwhile, a real-time security test with lossless business is realized, high continuity and high availability of electric power production business are guaranteed, and secondly, the security of the electric power information system is improved. The intelligent and automatic testing process is realized, and the testing efficiency and the accurate decision-making capability of safety management are greatly improved.
Owner:STATE GRID HENAN ELECTRIC POWER CO WENXIAN POWER SUPPLY CO