Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

18 results about "Signature database" patented technology

Security event detection method, system and device, medium and program product

The invention discloses a security event detection method, system and device, a medium and a program product, and the method comprises the steps: carrying out the feature extraction of to-be-detected security data, and obtaining a security data feature vector; based on a meta-feature vector corresponding to the security data feature vector and at least two preset security event analysis units, performing dynamic analysis on the security data feature vector to obtain a security event analysis result; and according to the security event analysis result, performing security event identification on the to-be-detected security data to obtain a security event identification result. According to the invention, the security event analysis unit can be dynamically selected based on the element feature vector corresponding to the security data feature vector so as to realize dynamic analysis of the security data feature vector, so that the dynamic analysis is not limited to predetermined detection rules in a static rule library and a feature signature library; the method can effectively identify unknown threats, zero-day attacks and continuously variable malicious behaviors, significantly improves the security event detection precision, and reduces the missing report rate of security events.
Owner:CHINA MOBILE GRP FUJIAN CO LTD +1

Application assurance system having a method of offloading service from an edge device to the cloud

A cloud-based application assurance service system and method using Deep Packet Inspection (DPI) enables Network Elements (NE) to access the cloud-based application assurance service to search a rules / signature database, without impacting latency on network-firewall decisions. Additionally, the application assurance service system distributes the associated mapping of the NE cache's latest contents to neighboring NEs, where a given user might next access the network. The system can recognize applications associated with network traffic and apply firewall rules. Further, the system tracks applications and uses this data to update NE caches periodically, such that NE caches are more likely to store the relevant application signatures in advance. Moreover, a historical user usage matrix is generated to track application use per user, which is used to detect a highly probable user path and transfer mapping to an associated NE.
Owner:HEWLETT PACKARD ENTERPRISE DEV LP

Evaluating source contribution to generated content

Evaluating the presence of training data in generated content by defining a first signature of a portion of the generated content by loading the generated content into memory registers, dividing the generated content into tokens, designating a sequential group of tokens as a signature shingle, and defining the first signature as a hash function value for the signature shingle. The evaluation also including matching the first signature to a training data signature in a training data signature database, updating a database record for the generated content to include the training data associated with the training data signature, and providing an output comprising data associated with the training data signature over a network.
Owner:INTERNATIONAL BUSINESS MACHINE CORPORATION

Batch antivirus method based on SSHFS mounting

The invention discloses a batch antivirus method based on SSHFS mounting, which relates to the technical field of information security, and comprises the following steps: dividing three logically independent node spaces on host source equipment; according to the method, three logic spaces including the control node, the software library node and the trust and isolation node are divided on the host source equipment, an antivirus program and a feature library on the host source equipment are mounted to the target equipment in a remote directory form based on the SSHFS, and the target equipment does not need to be provided with complete antivirus software in advance; all target devices share a unified program and a feature library on a host source device, when an administrator updates, the updating operation is only executed once at a center node and is automatically synchronized to mounting directories of all devices through SSHFS, all data transmission is carried out in an encryption channel, and the data transmission efficiency is improved. Task scheduling, environment mounting, remote scanning, result recovery, log analysis and report generation are integrated into an automatic process, SSHFS mounting is automatically relieved after a task is completed, and a temporary directory and cache on target equipment are cleared.
Owner:BEIJING CATHAY INTERNET INFORMATION TECH CO LTD +1

Identification method for signature in image, electronic equipment, storage medium and program product

PendingCN121838194AInstrumentsEngineeringTarget signature
The invention discloses a method for identifying a signature in an image, electronic equipment, a storage medium and a program product. The method comprises the following steps: carrying out feature extraction on a signature image to obtain signature features; obtaining a target signature feature successfully matched with the signature feature from a plurality of preset signature features in a preset signature database; a target signature rule corresponding to the target signature feature is determined from a preset rule base, and preset signature rules corresponding to a plurality of preset signature features are stored in the preset rule base; and identifying the signature feature based on the target signature rule to obtain an identification result of the signature image, the identification result being used for representing whether the signature image satisfies the target signature rule. According to the invention, the technical problem of low identification efficiency of the signature in the image in the prior art is solved.
Owner:CHINA CONSTRUCTION BANK +1

Heterogeneous environment vulnerability verification system and method, computer device

PendingCN122365498AVirtualizationData matching
This application provides a vulnerability verification system and method for heterogeneous environments, as well as a computer device. The system includes: a vulnerability signature database for storing vulnerability signature data of multiple vulnerabilities; an adaptive scanning engine for determining a target verification strategy matching the vulnerability to be verified from the vulnerability signature data; a virtualized verification environment for verifying the vulnerability to be verified based on the target verification strategy and obtaining verification results; a risk assessment module for determining reference vulnerability signature data matching the vulnerability to be verified from the vulnerability signature data, and performing a risk assessment on the vulnerability to be verified based on the reference vulnerability signature data and the verification results, and obtaining a risk assessment result; and a remediation suggestion generator for determining a target vulnerability remediation strategy matching the risk assessment result from the vulnerability signature data, and remediating the vulnerability to be verified based on the target vulnerability remediation strategy.
Owner:CHENGDU KAIYUAN COMPUTING ECOLOGICAL TECHNOLOGY CO LTD

Method and apparatus for estimating a location of a platform

There is disclosed a method for determining a location of a platform in a region. The platform comprises an event camera having an array of pixels and a memory store. Each pixel is operable to output events which represent a change in light intensity recorded at that pixel. Before platform motion in the region, a signature database is stored in the memory store. Each of the signatures has an associated patch at a known location, and each signature represents the number of events that would be captured by viewing the associated patch using the event camera whilst moving the sightline of the event camera through each of a predetermined set of intervals on a predetermined trajectory. During platform motion in the region, the platform location is determined by using the event camera to obtain a sensed signature. The sensed signature is compared to the signature database to locate the platform.
Owner:MBDA UK

Evaluating source contribution to generated content

Evaluating the presence of training data in generated content by defining a first signature of a portion of the generated content by loading the generated content into memory registers, dividing the generated content into tokens, designating a sequential group of tokens as a signature shingle, and defining the first signature as a hash function value for the signature shingle. The evaluation also including matching the first signature to a training data signature in a training data signature database, updating a database record for the generated content to include the training data associated with the training data signature, and providing an output comprising data associated with the training data signature over a network.
Owner:INTERNATIONAL BUSINESS MACHINE CORPORATION +2

A method, apparatus and storage medium for detecting and removing malicious code

This invention proposes a method, apparatus, and storage medium for detecting and removing malicious code, relating to the field of computer system security technology. The method includes the following steps: merging a malicious code signature database with a first malicious code removal program to form a second malicious code removal program; reading malicious code signature data from the second malicious code removal program into memory; invoking the second malicious code removal program to traverse all files on the disk, comparing the files with the malicious code signature data in memory; if a file matches the malicious code signature data, it is determined to be malicious code; if a file does not match the malicious code signature data, it is determined to be non-malicious code. This method addresses the problem of malicious code signature database files stored separately on the disk being analyzed and reverse engineered. This invention also provides a malicious file removal apparatus and a computer-readable storage medium, both possessing the aforementioned beneficial effects.
Owner:BEIJING KINGSOFT SECURITY MANAGEMENT SYST TECH CO LTD

A satellite firmware program reverse analysis method based on signature mechanism and taint analysis

The application discloses a kind of satellite firmware program reverse analysis methods based on signature mechanism and taint analysis.The method is by identifying encryption function, decrypting firmware content and tracking data flow, analysis program logic and dependency, to clarify the implementation of authentication and communication mechanism, and restore normal code logic.Specifically including:1) by constructing encryption function signature database, using static analysis tool and signature library matching, quickly identify encryption or decryption function in firmware;2) using Bi-LSTM neural network, similarity calculation is carried out to target code and vulnerability template, so as to track data flow and analyze program logic;3) comprehensive encryption function identification and data flow tracking result, parse communication protocol and authentication mechanism, restore its implementation logic.The application overcomes the problem of low efficiency and insufficient automation of traditional reverse analysis method, can significantly improve the precision and efficiency of firmware reverse analysis.In particular, when dealing with complex data flow and custom function, the data flow in business logic can be effectively clarified, thereby providing security for satellite ground station equipment.
Owner:KNOWYOU INFORMATION TECH SHANGHAI

Methods and apparatus to generate reference signatures

ActiveUS12593102B2Broadcast components for monitoring/identification/recognitionBroadcast information monitoringData scienceData bank
Methods and apparatus to generate reference signatures are disclosed. An example method includes collecting a first signature for media being presented to a plurality of households; crediting the media when the first signature matches a reference signature in a reference signature database; in response to determining that the first signature does not match a reference signature in the reference signature database and the first signature does not match an unidentified signature in an unknown signature database, storing the first signature in the unknown signature database; in response to determining that a second signature does not match the reference signature in the reference signature database and the second signature matches the unidentified signature in the unknown signature database, and increasing a count associated with the unidentified signature.
Owner:THE NIELSEN CO (US) LLC

Industrial mobile storage medium security management and control system and management and control method

The invention discloses an industrial mobile storage medium security management and control system and a management and control method, and relates to the field of industrial control system network security. Virus is introduced into a mobile storage medium in a physical isolation industrial network, and a reliable management and control closed loop cannot be formed by depending on management and a single technical means. The mobile medium security inspection station is internally provided with an anti-virus engine and a virus feature library, virus searching and killing are carried out on the inserted mobile storage medium, an anti-tamper virus killing mark is generated on the medium after searching and killing are completed, an industrial control host guard is deployed on a production network industrial host, access control verification is carried out on the mobile storage medium, and the security inspection efficiency is improved. And if the verification is not passed, the industrial host is prevented from reading the medium. According to the method, a label-free and non-reading technical closed loop is constructed, it is ensured that all the mobile storage media accessed to the production network are subjected to safety detection, and viruses are effectively prevented from being spread through the mobile storage media.
Owner:SHENGSI COUNTY POWER SUPPLY CO OF STATE GRID ZHEJIANG ELECTRIC POWER CO LTD

Methods and apparatus to generate reference signatures

PendingUS20260189753A1Data scienceData library
Methods and apparatus to generate reference signatures are disclosed. An example method includes collecting a first signature for media being presented to a plurality of households; crediting the media when the first signature matches a reference signature in a reference signature database; in response to determining that the first signature does not match a reference signature in the reference signature database and the first signature does not match an unidentified signature in an unknown signature database, storing the first signature in the unknown signature database; in response to determining that a second signature does not match the reference signature in the reference signature database and the second signature matches the unidentified signature in the unknown signature database, and increasing a count associated with the unidentified signature
Owner:THE NIELSEN CO (US) LLC

Magnetic resonance signature matching (MRSIGMA) for real-time volumetric motion tracking and adaptive radiotherapy

Described is an approach for tracking 3D organ motion in real-time using magnetic resonance imaging (MRI). The approach may include offline learning, which may acquire signature and 3D imaging data over multiple respiratory cycles to create a database of high-resolution 3D motion states. The approach may further include online matching, which may acquire signature data only in real-time (latency less than 0.2 seconds). From a motion state and motion signature database, the 3D motion state whose signature best (or sufficiently) matches the newly-acquired signature data may be selected. Real-time 3D motion tracking may be accomplished by performing time-consuming acquisition and reconstruction work in an offline learning phase, leaving just signature acquisition and correlation analysis in an online matching step, minimizing or otherwise reducing latency. The approach may be used to adapt radiotherapy procedures based on tumor motion using a magnetic resonance linear accelerator (MR-Linac) system.
Owner:MEMORIAL SLOAN KETTERING CANCER CENT

A network security management method, device, equipment and machine readable storage medium

ActiveCN116318903BAttackIntrusion prevention system
This disclosure provides a network security management method, apparatus, device, and machine-readable storage medium. The method includes: obtaining attack signature IDs of attack features identified as false alarms based on an enabled false alarm prevention function; adding the attack signature IDs identified as false alarms to a false alarm prevention hash table; obtaining each attack signature ID associated with each attack behavior reported by the detection engine; matching the obtained attack signature IDs in the false alarm prevention hash table; and determining that the attack behavior associated with the successfully matched attack signature ID is a false alarm. Through the technical solution of this disclosure, for intrusion prevention systems that cannot promptly change or configure the signature database, a whitelist is established based on the attack signature IDs associated with attack behaviors determined to be false alarms. Subsequently, when an attack behavior associated with the same attack signature ID is detected again, it is directly considered a false alarm and the relevant packets are allowed to pass, thereby reducing the false alarm rate.
Owner:NEW H3C SECURITY TECH CO LTD

Trojan process positioning method and device with minute level, equipment and medium

PendingCN122365496ADirectoryProcess information
This application provides a method, apparatus, device, and medium for locating Trojan processes within minutes. The method includes: performing non-full-disk targeted fingerprint verification on monitoring binary files in the system to be repaired based on a Trojan tampering signature database and preset verification rules to identify system monitoring files modified by Trojan processes, obtaining a standard monitoring file corresponding to the system monitoring file, and replacing the system monitoring file with the standard monitoring file; using a batch unhiding strategy combined with security experience rules to remove Trojan hidden kernel modules in the system to be repaired; and performing a non-full-disk targeted parallel scan on high-frequency Trojan hiding directories in the system to be repaired through process information tracing and security experience rules to locate the executable file and startup file of the Trojan process within minutes, deleting the executable file and startup file from the original directory, and temporarily restoring user services. This achieves efficient location and removal of Trojans, meeting the needs of emergency recovery operations in production environments.
Owner:HASHPOWER INTERNET (BEIJING) TECH CO LTD

Method and system for dynamically checking seal by combining manufacturing industrial drawings

The invention relates to the technical field of data processing, and particularly discloses a method and a system for combining and dynamically checking stamps of drawings in the manufacturing industry. Multi-category drawing files uploaded by a user are received, a responsible person information database is obtained, and first checking and stamping information of drawing files corresponding to the multi-category drawing files is read; querying a responsible person information database according to a flow node corresponding to the drawing file, determining a responsible person information list corresponding to the first seal checking information, obtaining template region information in a signature database as second seal checking information, and executing a double comparison checking mechanism according to the first seal checking information and the second seal checking information to determine a signature region. According to the technical scheme, the signature database is called for signature for the signature area, all the signed drawing files are merged page by page according to the preset sequence, automation and standardization of drawing signature and merging are achieved, the efficiency of multi-drawing processing is remarkably improved, and traceability and normalization of the signature sequence and the merging result are guaranteed.
Owner:NANJING HENTOR INFOMATION TECH CO LTD

Mark authentication with distortion tolerance

Methods, systems, and apparatus, including medium-encoded computer program products, for mark authentication with distortion tolerance. An electronic signature can be obtained as the data series for a candidate mark. The data series values of the electronic signature can be transformed to generate two or more transformed data series versions of the electronic signature. Hash identifiers for the electronic signature and for the two or more transformed data series versions of the electronic signature can be derived. The hash identifiers can be used to retrieve a set of two or more results from a database of genuine mark signatures. At least one electronic signature retrieved for at least one of the two or more results from the database can be compared with the electronic signature for the candidate mark to confirm the candidate mark is genuine.
Owner:SYS TECH SOLUTIONS INC