Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

27 results about "Signature database" patented technology

Security event detection method, system and device, medium and program product

The invention discloses a security event detection method, system and device, a medium and a program product, and the method comprises the steps: carrying out the feature extraction of to-be-detected security data, and obtaining a security data feature vector; based on a meta-feature vector corresponding to the security data feature vector and at least two preset security event analysis units, performing dynamic analysis on the security data feature vector to obtain a security event analysis result; and according to the security event analysis result, performing security event identification on the to-be-detected security data to obtain a security event identification result. According to the invention, the security event analysis unit can be dynamically selected based on the element feature vector corresponding to the security data feature vector so as to realize dynamic analysis of the security data feature vector, so that the dynamic analysis is not limited to predetermined detection rules in a static rule library and a feature signature library; the method can effectively identify unknown threats, zero-day attacks and continuously variable malicious behaviors, significantly improves the security event detection precision, and reduces the missing report rate of security events.
Owner:CHINA MOBILE GRP FUJIAN CO LTD +1

Diagnostic tool for traffic capture with known signature database

A method of identifying error patterns during automated device testing comprises receiving a data pattern from a plurality of capture modules programmed on a programmable logic device, wherein the plurality of capture modules are programmable and operable to selectively capture data traffic to be monitored, and wherein the data traffic comprises a flow of traffic between a DUT and the programmable logic device. The method further comprises comparing the data pattern with known signatures in an error signature database. Also, the method comprises correlating the data pattern with one or more matching known signatures in the error signature database and assigning a score to each of the one or more matching known signatures in the error signature database based a level of correlation.
Owner:ADVANTEST CORP

Application assurance system having a method of offloading service from an edge device to the cloud

A cloud-based application assurance service system and method using Deep Packet Inspection (DPI) enables Network Elements (NE) to access the cloud-based application assurance service to search a rules / signature database, without impacting latency on network-firewall decisions. Additionally, the application assurance service system distributes the associated mapping of the NE cache's latest contents to neighboring NEs, where a given user might next access the network. The system can recognize applications associated with network traffic and apply firewall rules. Further, the system tracks applications and uses this data to update NE caches periodically, such that NE caches are more likely to store the relevant application signatures in advance. Moreover, a historical user usage matrix is generated to track application use per user, which is used to detect a highly probable user path and transfer mapping to an associated NE.
Owner:HEWLETT PACKARD ENTERPRISE DEV LP

Evaluating source contribution to generated content

Evaluating the presence of training data in generated content by defining a first signature of a portion of the generated content by loading the generated content into memory registers, dividing the generated content into tokens, designating a sequential group of tokens as a signature shingle, and defining the first signature as a hash function value for the signature shingle. The evaluation also including matching the first signature to a training data signature in a training data signature database, updating a database record for the generated content to include the training data associated with the training data signature, and providing an output comprising data associated with the training data signature over a network.
Owner:INTERNATIONAL BUSINESS MACHINE CORPORATION

Digital asset transaction system and method for operating same

The present invention relates to a digital asset transaction system for supporting transactions of digital assets and to a method for operating same. An electronic device included in the digital asset transaction system may: generate a temporary identifier for identifying a digital transaction and provide the temporary identifier to a counterpart device; and identify whether a recipient address for performing the digital transaction is valid by using digital signature data obtained by querying an address-signature database on the basis of a substitute identifier and a random personal identification number provided by the counterpart device in response to the temporary identifier.
Owner:SAMSUNG ELECTRONICS CO LTD

Batch antivirus method based on SSHFS mounting

The invention discloses a batch antivirus method based on SSHFS mounting, which relates to the technical field of information security, and comprises the following steps: dividing three logically independent node spaces on host source equipment; according to the method, three logic spaces including the control node, the software library node and the trust and isolation node are divided on the host source equipment, an antivirus program and a feature library on the host source equipment are mounted to the target equipment in a remote directory form based on the SSHFS, and the target equipment does not need to be provided with complete antivirus software in advance; all target devices share a unified program and a feature library on a host source device, when an administrator updates, the updating operation is only executed once at a center node and is automatically synchronized to mounting directories of all devices through SSHFS, all data transmission is carried out in an encryption channel, and the data transmission efficiency is improved. Task scheduling, environment mounting, remote scanning, result recovery, log analysis and report generation are integrated into an automatic process, SSHFS mounting is automatically relieved after a task is completed, and a temporary directory and cache on target equipment are cleared.
Owner:BEIJING CATHAY INTERNET INFORMATION TECH CO LTD +1

Identification method for signature in image, electronic equipment, storage medium and program product

The invention discloses a method for identifying a signature in an image, electronic equipment, a storage medium and a program product. The method comprises the following steps: carrying out feature extraction on a signature image to obtain signature features; obtaining a target signature feature successfully matched with the signature feature from a plurality of preset signature features in a preset signature database; a target signature rule corresponding to the target signature feature is determined from a preset rule base, and preset signature rules corresponding to a plurality of preset signature features are stored in the preset rule base; and identifying the signature feature based on the target signature rule to obtain an identification result of the signature image, the identification result being used for representing whether the signature image satisfies the target signature rule. According to the invention, the technical problem of low identification efficiency of the signature in the image in the prior art is solved.
Owner:CHINA CONSTRUCTION BANK +1

Heterogeneous environment vulnerability verification system and method, computer device

PendingCN122365498AVirtualizationData matching
This application provides a vulnerability verification system and method for heterogeneous environments, as well as a computer device. The system includes: a vulnerability signature database for storing vulnerability signature data of multiple vulnerabilities; an adaptive scanning engine for determining a target verification strategy matching the vulnerability to be verified from the vulnerability signature data; a virtualized verification environment for verifying the vulnerability to be verified based on the target verification strategy and obtaining verification results; a risk assessment module for determining reference vulnerability signature data matching the vulnerability to be verified from the vulnerability signature data, and performing a risk assessment on the vulnerability to be verified based on the reference vulnerability signature data and the verification results, and obtaining a risk assessment result; and a remediation suggestion generator for determining a target vulnerability remediation strategy matching the risk assessment result from the vulnerability signature data, and remediating the vulnerability to be verified based on the target vulnerability remediation strategy.
Owner:CHENGDU KAIYUAN COMPUTING ECOLOGICAL TECHNOLOGY CO LTD

Method and apparatus for estimating a location of a platform

There is disclosed a method for determining a location of a platform in a region. The platform comprises an event camera having an array of pixels and a memory store. Each pixel is operable to output events which represent a change in light intensity recorded at that pixel. Before platform motion in the region, a signature database is stored in the memory store. Each of the signatures has an associated patch at a known location, and each signature represents the number of events that would be captured by viewing the associated patch using the event camera whilst moving the sightline of the event camera through each of a predetermined set of intervals on a predetermined trajectory. During platform motion in the region, the platform location is determined by using the event camera to obtain a sensed signature. The sensed signature is compared to the signature database to locate the platform.
Owner:MBDA UK

Evaluating source contribution to generated content

Evaluating the presence of training data in generated content by defining a first signature of a portion of the generated content by loading the generated content into memory registers, dividing the generated content into tokens, designating a sequential group of tokens as a signature shingle, and defining the first signature as a hash function value for the signature shingle. The evaluation also including matching the first signature to a training data signature in a training data signature database, updating a database record for the generated content to include the training data associated with the training data signature, and providing an output comprising data associated with the training data signature over a network.
Owner:INTERNATIONAL BUSINESS MACHINE CORPORATION +2

Reconfiguring a second type of sensor based on sensing data of a first type of sensor

Methods and system to learn precise sensing fingerprints based on machine learning integration are disclosed herein. In use, the system receives at least one first parameter associated with at least one sensor and associates the first parameter with a pre-identified first digital signature in a signature database. A machine learning system is trained based on the first parameter and the pre-identified digital signature. The system then receives at least one second parameter from the at least one sensor and determines that the second parameter is independent of a digital signature in the signature database. Using the machine learning system, a second digital signature for the second parameter is identified and saved in the signature database.
Owner:LYTEN INC

A method, apparatus and storage medium for detecting and removing malicious code

This invention proposes a method, apparatus, and storage medium for detecting and removing malicious code, relating to the field of computer system security technology. The method includes the following steps: merging a malicious code signature database with a first malicious code removal program to form a second malicious code removal program; reading malicious code signature data from the second malicious code removal program into memory; invoking the second malicious code removal program to traverse all files on the disk, comparing the files with the malicious code signature data in memory; if a file matches the malicious code signature data, it is determined to be malicious code; if a file does not match the malicious code signature data, it is determined to be non-malicious code. This method addresses the problem of malicious code signature database files stored separately on the disk being analyzed and reverse engineered. This invention also provides a malicious file removal apparatus and a computer-readable storage medium, both possessing the aforementioned beneficial effects.
Owner:BEIJING KINGSOFT SECURITY MANAGEMENT SYST TECH CO LTD

Mark authentication with distortion tolerance

Methods, systems, and apparatus, including medium-encoded computer program products, for mark authentication with distortion tolerance. An electronic signature can be obtained as the data series for a candidate mark. The data series values of the electronic signature can be transformed to generate two or more transformed data series versions of the electronic signature. Hash identifiers for the electronic signature and for the two or more transformed data series versions of the electronic signature can be derived. The hash identifiers can be used to retrieve a set of two or more results from a database of genuine mark signatures. At least one electronic signature retrieved for at least one of the two or more results from the database can be compared with the electronic signature for the candidate mark to confirm the candidate mark is genuine.
Owner:SYS TECH SOLUTIONS INC

A satellite firmware program reverse analysis method based on signature mechanism and taint analysis

The application discloses a kind of satellite firmware program reverse analysis methods based on signature mechanism and taint analysis.The method is by identifying encryption function, decrypting firmware content and tracking data flow, analysis program logic and dependency, to clarify the implementation of authentication and communication mechanism, and restore normal code logic.Specifically including:1) by constructing encryption function signature database, using static analysis tool and signature library matching, quickly identify encryption or decryption function in firmware;2) using Bi-LSTM neural network, similarity calculation is carried out to target code and vulnerability template, so as to track data flow and analyze program logic;3) comprehensive encryption function identification and data flow tracking result, parse communication protocol and authentication mechanism, restore its implementation logic.The application overcomes the problem of low efficiency and insufficient automation of traditional reverse analysis method, can significantly improve the precision and efficiency of firmware reverse analysis.In particular, when dealing with complex data flow and custom function, the data flow in business logic can be effectively clarified, thereby providing security for satellite ground station equipment.
Owner:KNOWYOU INFORMATION TECH SHANGHAI

Methods and apparatus to generate reference signatures

Methods and apparatus to generate reference signatures are disclosed. An example method includes collecting a first signature for media being presented to a plurality of households; crediting the media when the first signature matches a reference signature in a reference signature database; in response to determining that the first signature does not match a reference signature in the reference signature database and the first signature does not match an unidentified signature in an unknown signature database, storing the first signature in the unknown signature database; in response to determining that a second signature does not match the reference signature in the reference signature database and the second signature matches the unidentified signature in the unknown signature database, and increasing a count associated with the unidentified signature.
Owner:THE NIELSEN CO (US) LLC

Method for determining type of specification of smart contract on blockchain and server for executing same

A server for determining the type of specification of a smart contract according to the present invention comprises: a specification database in which a function of a smart contract performing a specific function according to an ERC standard and parameters used in the function are configured and stored as a signature; a byte code signature database in which a signature extracted from a byte code existing on a blockchain is stored; and a specification verification unit that, when receiving a request message for verifying the standard specification of a smart contract from a smart contract user terminal, verifies the specification of the smart contract on the basis of the specification database and the byte code signature database.
Owner:CCMEDIA SERVICE CO LTD

Industrial mobile storage medium security management and control system and management and control method

The invention discloses an industrial mobile storage medium security management and control system and a management and control method, and relates to the field of industrial control system network security. Virus is introduced into a mobile storage medium in a physical isolation industrial network, and a reliable management and control closed loop cannot be formed by depending on management and a single technical means. The mobile medium security inspection station is internally provided with an anti-virus engine and a virus feature library, virus searching and killing are carried out on the inserted mobile storage medium, an anti-tamper virus killing mark is generated on the medium after searching and killing are completed, an industrial control host guard is deployed on a production network industrial host, access control verification is carried out on the mobile storage medium, and the security inspection efficiency is improved. And if the verification is not passed, the industrial host is prevented from reading the medium. According to the method, a label-free and non-reading technical closed loop is constructed, it is ensured that all the mobile storage media accessed to the production network are subjected to safety detection, and viruses are effectively prevented from being spread through the mobile storage media.
Owner:SHENGSI COUNTY POWER SUPPLY CO OF STATE GRID ZHEJIANG ELECTRIC POWER CO LTD

Methods and apparatus to generate reference signatures

PendingUS20260189753A1Data scienceData library
Methods and apparatus to generate reference signatures are disclosed. An example method includes collecting a first signature for media being presented to a plurality of households; crediting the media when the first signature matches a reference signature in a reference signature database; in response to determining that the first signature does not match a reference signature in the reference signature database and the first signature does not match an unidentified signature in an unknown signature database, storing the first signature in the unknown signature database; in response to determining that a second signature does not match the reference signature in the reference signature database and the second signature matches the unidentified signature in the unknown signature database, and increasing a count associated with the unidentified signature
Owner:THE NIELSEN CO (US) LLC

Magnetic resonance signature matching (MRSIGMA) for real-time volumetric motion tracking and adaptive radiotherapy

Described is an approach for tracking 3D organ motion in real-time using magnetic resonance imaging (MRI). The approach may include offline learning, which may acquire signature and 3D imaging data over multiple respiratory cycles to create a database of high-resolution 3D motion states. The approach may further include online matching, which may acquire signature data only in real-time (latency less than 0.2 seconds). From a motion state and motion signature database, the 3D motion state whose signature best (or sufficiently) matches the newly-acquired signature data may be selected. Real-time 3D motion tracking may be accomplished by performing time-consuming acquisition and reconstruction work in an offline learning phase, leaving just signature acquisition and correlation analysis in an online matching step, minimizing or otherwise reducing latency. The approach may be used to adapt radiotherapy procedures based on tumor motion using a magnetic resonance linear accelerator (MR-Linac) system.
Owner:MEMORIAL SLOAN KETTERING CANCER CENT

Network attack detection method and apparatus

A network attack detection method and apparatus is provided. The network protection device obtains first key data from received first network traffic, and matches the first key data with an attack signature in a signature database to obtain a first matching result; if the network protection device determines, based on the first matching result, that the first network traffic is aggressive, the network protection device obtains a target attack detection model based on the first network traffic, where the target attack detection model is used to identify one or more attack signatures that are different from the attack signature in the signature database; and when the network protection device receives second network traffic, the network protection device determines, based on the target attack detection model, whether the second network traffic is aggressive.
Owner:HUAWEI TECH CO LTD

A network security management method, device, equipment and machine readable storage medium

ActiveCN116318903BAttackIntrusion prevention system
This disclosure provides a network security management method, apparatus, device, and machine-readable storage medium. The method includes: obtaining attack signature IDs of attack features identified as false alarms based on an enabled false alarm prevention function; adding the attack signature IDs identified as false alarms to a false alarm prevention hash table; obtaining each attack signature ID associated with each attack behavior reported by the detection engine; matching the obtained attack signature IDs in the false alarm prevention hash table; and determining that the attack behavior associated with the successfully matched attack signature ID is a false alarm. Through the technical solution of this disclosure, for intrusion prevention systems that cannot promptly change or configure the signature database, a whitelist is established based on the attack signature IDs associated with attack behaviors determined to be false alarms. Subsequently, when an attack behavior associated with the same attack signature ID is detected again, it is directly considered a false alarm and the relevant packets are allowed to pass, thereby reducing the false alarm rate.
Owner:NEW H3C SECURITY TECH CO LTD

Trojan process positioning method and device with minute level, equipment and medium

PendingCN122365496ADirectoryProcess information
This application provides a method, apparatus, device, and medium for locating Trojan processes within minutes. The method includes: performing non-full-disk targeted fingerprint verification on monitoring binary files in the system to be repaired based on a Trojan tampering signature database and preset verification rules to identify system monitoring files modified by Trojan processes, obtaining a standard monitoring file corresponding to the system monitoring file, and replacing the system monitoring file with the standard monitoring file; using a batch unhiding strategy combined with security experience rules to remove Trojan hidden kernel modules in the system to be repaired; and performing a non-full-disk targeted parallel scan on high-frequency Trojan hiding directories in the system to be repaired through process information tracing and security experience rules to locate the executable file and startup file of the Trojan process within minutes, deleting the executable file and startup file from the original directory, and temporarily restoring user services. This achieves efficient location and removal of Trojans, meeting the needs of emergency recovery operations in production environments.
Owner:HASHPOWER INTERNET (BEIJING) TECH CO LTD

Application program loading method, electronic equipment and storage medium

The invention discloses an application program loading method, electronic equipment and a storage medium, and the method comprises the steps: carrying out the signature verification of a signature database file corresponding to an application program through a preset digital signature, and determining the successfully verified application program as a target application program, the signature database file is determined by utilizing a first digest value corresponding to a loading class contained in the application program, and the first digest value is generated when the application program is packaged; a second abstract value corresponding to a to-be-loaded target loading class of the target application program is obtained, and the second abstract value is generated when the target loading class needs to be loaded; in response to the fact that the second digest value is consistent with the corresponding first digest value, loading the target loading class, and then completing loading of the target application program; according to the method and the device, malicious loading classes are effectively identified and blocked, the situations of false report and missing report are reduced, the detection accuracy is improved, and the cost is reduced.
Owner:ZHEJIANG DAHUA TECH CO LTD

Method and system for dynamically checking seal by combining manufacturing industrial drawings

The invention relates to the technical field of data processing, and particularly discloses a method and a system for combining and dynamically checking stamps of drawings in the manufacturing industry. Multi-category drawing files uploaded by a user are received, a responsible person information database is obtained, and first checking and stamping information of drawing files corresponding to the multi-category drawing files is read; querying a responsible person information database according to a flow node corresponding to the drawing file, determining a responsible person information list corresponding to the first seal checking information, obtaining template region information in a signature database as second seal checking information, and executing a double comparison checking mechanism according to the first seal checking information and the second seal checking information to determine a signature region. According to the technical scheme, the signature database is called for signature for the signature area, all the signed drawing files are merged page by page according to the preset sequence, automation and standardization of drawing signature and merging are achieved, the efficiency of multi-drawing processing is remarkably improved, and traceability and normalization of the signature sequence and the merging result are guaranteed.
Owner:NANJING HENTOR INFOMATION TECH CO LTD

Mark authentication with distortion tolerance

Methods, systems, and apparatus, including medium-encoded computer program products, for mark authentication with distortion tolerance. An electronic signature can be obtained as the data series for a candidate mark. The data series values of the electronic signature can be transformed to generate two or more transformed data series versions of the electronic signature. Hash identifiers for the electronic signature and for the two or more transformed data series versions of the electronic signature can be derived. The hash identifiers can be used to retrieve a set of two or more results from a database of genuine mark signatures. At least one electronic signature retrieved for at least one of the two or more results from the database can be compared with the electronic signature for the candidate mark to confirm the candidate mark is genuine.
Owner:SYS TECH SOLUTIONS INC

System and method for monitoring touch events in a cockpit display

A system for monitoring touch events in a cockpit display includes one or more user monitoring devices including eye tracking sensors and body tracking sensors. The system includes a controller including a touch event algorithm configured to determine inadvertent touch events. The controller may receive eye gaze and body movement data of the user viewing the display. The controller may receive the spatial-temporal touch event data and compare the spatial-temporal touch event data with touch event signature data in a touch event signature database. The controller may determine whether the received user touch input is an inadvertent touch event. Upon determining the user touch input is an inadvertent touch, the controller may perform a first set of avionic system actions and upon determining the user touch input is an intentional touch, the controller may perform a second set of avionic system actions.
Owner:ROCKWELL COLLINS INC

Virus searching and killing method and system for distributed energy security data

A virus searching and killing method and system for distributed energy security data relates to the field of virus processing, and comprises the following steps: acquiring an original feature code of a virus, splitting the original feature code into N discontinuous and sequential fixed fragments Fi, calculating an initial offset Si of each fragment Fi relative to a first fragment F1, and constructing a virus feature database, according to the method, firstly, a data stream is divided into a plurality of data blocks Bi with the fixed size, scanning and matching association are conducted through a sliding window with the fixed size, and finally threshold judgment is conducted. Original virus feature codes are subjected to fragmentation processing, and the storage requirement of a virus feature database is lowered; secondly, sliding window scanning can ensure that any feature combination is covered, a matching event FPi is recorded instead of full data, and memory occupation is reduced; by comparing the absolute offset SBi with the expected position, the correct sequence of the fragments in the virus is ensured, the matching progress can be tracked in real time by a state machine, weights are accumulated only for the fragments with the correct sequence, and the detection credibility is improved.
Owner:HUNAN XINHE ENERGY SERVICES CO LTD