Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

16 results about "Software behavior" patented technology

A multi-level protocol software dangerous behavior detection method

ActiveCN121859332BPlatform integrity maintainanceTemporal logicLinguistic model
The application belongs to the technical field of software dangerous behavior detection, and is a multi-level specification software dangerous behavior detection method, comprising the following steps: setting a positive and negative example set and a distance measurement function for quantifying the similarity degree of software behavior sequences, and dividing the positive example set into a plurality of positive example subsets; constructing a temporal logic specification weight tree as a triple consisting of a root node weight function, a left child formula depth weight function and a right child formula depth weight function; extracting positive examples from the positive example subsets to form a positive example reduced set; inquiring a large language model to obtain software dangerous behavior logic formulas and converting the software dangerous behavior logic formulas into equivalent finite state automata; sampling a negative example reduced set from the automata; inquiring the large language model based on the positive and negative example reduced sets multiple times to obtain formula fragments, dynamically updating the weight tree, and obtaining candidate formulas; and selecting the optimal candidate formula as a temporal logic specification to detect whether the software behavior sequence conforms to the temporal logic specification. The application alleviates the challenges of scarce dangerous behavior data and a too large dangerous behavior search space.
Owner:SUN YAT SEN UNIV

Software fault detection method based on software behavior analysis and intelligent reasoning

The invention discloses a software fault detection method based on software behavior analysis and intelligent reasoning, belongs to the technical field of computer system software, and aims to solve the technical problems of low efficiency and poor accuracy of a current traditional software fault detection mode and improve the troubleshooting efficiency. According to the technical scheme, the method comprises the steps that firstly, software behaviors are defined, file access, memory operation and other types are covered, software codes are scanned, the behaviors are recorded in detail, recording formats are defined, including recording time, code positions and other information, and then a software behavior fault model is established; secondly, defining fault log information including fault time, register values and the like, and constructing an analysis mechanism; when the log is analyzed, the log is read and analyzed, the fault position and the initial reason are judged, the final reason is determined in combination with the fault code, and finally the fault code position and condition are determined according to the model. The software fault can be efficiently detected and positioned, manual intervention is greatly reduced, the software stability and reliability are improved, and the method is suitable for various software fault detection scenes.
Owner:CHINA THREE GORGES UNIV

Software verification method and device, equipment, medium and program product

The invention provides a software verification method and device, equipment, a medium and a program product, and can be applied to the technical field of software management and artificial intelligence. The method comprises the steps that in response to obtained information of to-be-verified software, identity information and behavior information of the to-be-verified software are extracted, and the identity information comprises at least one of a program name, a version number, an installation date, a digital signature or a file hash value; the behavior information comprises at least one of resource occupation, a network connection behavior, a file operation behavior or a running time period; whether the identity information of the to-be-verified software is matched with a pre-configured software standard information base white list or not is verified, whether the behavior information accords with a predetermined software behavior baseline or not is verified, and the baseline is established according to historical behavior information of normal software identical to the to-be-verified software; and if both the identity information and the behavior information pass verification, determining that the to-be-verified software is normal software.
Owner:CHINA CONSTRUCTION BANK +1

Processor system structure state extraction method based on instruction injection

The invention provides a processor system structure state extraction method based on instruction injection, which comprises the following steps of: S1, acquiring a written debugging program, and implanting the debugging program into an illegal instruction exception handling function of software to be tested, the debugging program is triggered by a specified illegal instruction word injected by a user to read the system structure state of the simulation processor, and the system structure state comprises state information of a register and a memory; s2, embedding a microstructure mark in hardware of a simulation processor running on the software behavior simulator so as to provide a controllable operation point for injecting a specified illegal instruction word for the simulator; s3, when the system structure state of the simulation processor needs to be extracted, specified illegal instruction words are injected into the simulation processor through the microstructure marks, the simulation processor enters an exception handling process under the condition that the simulator determines that the specified illegal instruction words are received, and the system structure state of the simulation processor is extracted. And automatically skipping to the debugging program by executing the exception handling function to extract and output the extracted architecture state.
Owner:INST OF COMPUTING TECH CHINESE ACAD OF SCI

User interrupt processing method and system

The invention discloses a user interrupt processing method and system, and belongs to the technical field of data transmission. The method comprises the following steps: when a user logic end of the FPGA requests to generate user interruption, notifying an upper computer through an XDMA IP (Extensible Direct Memory Access Internet Protocol); the upper computer receives the notification of generating the user interrupt, processes the user interrupt generated this time, and updates the state of a preset first register after processing is completed; the user logic end determines whether the upper computer completes processing of the user interruption generated this time or not according to the state of the first register, updates the state of a preset second register after determining that the processing is completed, and executes subsequent logic; and the upper computer determines whether the user interruption can be enabled again according to the state of the second register. Through bidirectional confirmation of the first register and the second register, software and hardware behaviors are strictly synchronized, and hardware time sequence requirements of XDMA IP are perfectly met, so that each interruption can be completely and correctly processed.
Owner:BEIJING INST OF ENVIRONMENTAL FEATURES

A vulnerability lossless detection method based on patch correlation behavior exploration

This invention relates to a non-destructive vulnerability detection method based on patch-related behavior exploration, belonging to the field of network security technology. This invention compares and analyzes the vulnerable versions and patch versions of binary software to explore the differences in software behavior introduced by the vulnerability patches, thereby generating non-destructive detection samples. This method can accurately detect the existence of known vulnerabilities while ensuring the normal operation of the software system.
Owner:BEIJING INST OF COMP TECH & APPL

Systems and methods for detecting malicious activity using a machine learning model tuned to a specific endpoint device

Disclosed herein are systems and method for detecting malicious activity using a tuned machine learning model. In one aspect, a method includes receiving a plurality of logs indicative of software behavior from a plurality of endpoint devices and generating a plurality of event sequences from the plurality of logs. The method includes training a global machine learning model using the plurality of event sequences to predict resultant events for a sequence of lead up events and classify whether the resultant events indicate malicious activity. The method includes, for each respective endpoint device of the plurality of endpoint devices, generating a testing dataset comprising a plurality of benign event sequences that occurred on the respective endpoint device. The method includes generating a tuned machine learning model for the respective endpoint device by retraining the global machine learning model using the testing dataset. The method includes executing the tuned machine learning model.
Owner:ACRONIS INT

Domestic chip and CAE (Computer Aided Engineering) software collaborative optimization method and system combined with AI (Artificial Intelligence) technology

The invention discloses a domestic chip and CAE software collaborative optimization method and system combined with an AI technology, and belongs to the technical field of collaborative optimization, and the method comprises the steps: obtaining, preprocessing and marking original data, and obtaining training data; the initialized AI model is trained, and a trained AI model is obtained; acquiring real-time state data and real-time load characteristics, inputting the real-time state data and the real-time load characteristics into the trained AI model to obtain an optimization decision, performing instruction translation on the optimization decision to obtain a specific control instruction, sending the specific control instruction to chip hardware, automatically adjusting hardware behaviors and / or operating an interface through software. And automatically adjusting software behaviors. According to the method, dynamic and systematic software and hardware collaborative optimization is realized through an AI-driven optimization closed loop, and meanwhile, relevant parameter indexes can be adjusted and optimized.
Owner:NEOLITHIC COBALT BLUE INFORMATION TECHNOLOGY CO LTD

Method and system for constructing digital twin interphone

The invention discloses a method and a system for constructing a digital twin interphone. The method comprises the following steps of: 1, realizing hardware state data acquisition, software behavior data acquisition and communication environment data acquisition in a mode of combining hardware circuit transformation and software code instrumentation; 2, constructing a structured twinborn database through data preprocessing, feature engineering processing and database structure and storage by using the massive and heterogeneous original data with timestamps collected in the step 1, and training by using a machine learning technology to obtain a digital twinborn model of the interphone; 3, loading the digital twinborn model generated in the step 2, providing a virtual CPU, peripheral and radio frequency environment, executing unmodified actual interphone software codes or binary files, integrating a reinforcement learning AI algorithm in the digital twinborn model, performing automatic search and optimization on software parameters in a simulation environment, and obtaining a simulation result; and by taking power consumption and performance as optimization targets, displaying a simulation result in the form of a time sequence curve and / or a thermodynamic diagram.
Owner:SAMHOO SCI & TECH CO LTD

System and method of software behavior analysis

There are provided a method and a system of software behavior analysis. The method comprises: retrieving data sources related to a software program and mapping a list of behaviors characterizing the software program. Additionally, the method can comprise analyzing the list of behaviors to obtain at least one trait of at least one of the behaviors, and / or transcoding the list of behaviors to corresponding natural language descriptions and presenting the natural language descriptions of the list of behaviors to a user on a Graphical user interface (GUI). There are further provided a method and a system of testing changes between different versions of a software program based on the software behavior mapping and analysis.
Owner:CODIUN

Software behavior anomaly detection system and method based on deep learning

The application discloses a software behavior anomaly detection system and method based on deep learning, which comprises a behavior monitoring module, an anomaly detection module, an adaptive protection module and a model evolution module.The behavior monitoring module is used for capturing the calling sequence and context semantic information of a process and extracting a multi-dimensional feature vector.The anomaly detection module is used for analyzing the multi-dimensional feature vector through a hierarchical neural symbolic network, outputting a fusion feature through dynamic weighting of a gated symbolic attention mechanism, triggering a causal inference engine and a dynamic response framework based on a reinforcement decision tree.The adaptive protection module comprises the causal inference engine and the dynamic response framework based on the reinforcement decision tree, adjusts the protection strength according to an environmental risk index, and feeds back a feedback signal to the anomaly detection module to optimize a threshold.The model evolution module is used for integrating an adversarial sample generator and an online incremental learning mechanism to realize self-evolution capability.The application effectively solves the problem of missed detection of periodic attacks and hidden vulnerabilities, and significantly suppresses false positives caused by feature misjudgment.
Owner:HANGZHOU DIANZI UNIV

Software behavior anomaly detection system and method based on deep learning

The invention discloses a software behavior anomaly detection system and method based on deep learning, and the system comprises a behavior monitoring module which is used for capturing a call sequence and context semantic information of a process, and extracting a multi-dimensional feature vector; the anomaly detection module is used for analyzing the multi-dimensional feature vectors through a hierarchical neural symbol network, outputting fusion features, dynamically weighting the fusion features through a gating symbol attention mechanism, and triggering a causal inference engine and a dynamic response framework based on an enhanced decision tree; the self-adaptive protection module comprises a causal inference engine and a dynamic response framework based on an enhanced decision tree, adjusts the protection intensity according to the environmental risk index, and transmits a feedback signal back to the anomaly detection module to optimize a threshold value; and the model evolution module is used for integrating an adversarial sample generator and an online incremental learning mechanism to realize the self-evolution capability. According to the method, the problem of leak detection of periodic attacks and hidden vulnerabilities is effectively solved, and meanwhile, false alarms caused by feature misjudgment are remarkably inhibited.
Owner:HANGZHOU DIANZI UNIV

Abnormal software behavior remote identification method and system for multi-player game terminal

PendingCN121997236Aensure authenticityEnsure standardizationVideo gamesData setLocal outlier factor
The invention discloses an abnormal software behavior remote identification method and system oriented to a multi-player game terminal, particularly relates to the technical field of chess and card game terminal safety protection, and is used for solving the problem that in the prior art, due to terminal isomerism, behavior characteristic data collection granularity is not uniform, and then remote identification effectiveness is reduced. Collection granularity information is synchronously bound when behavior characteristic data are collected at a terminal side, a server side verifies the integrity and granularity marking validity of the data after receiving the data, then cluster classification is carried out according to terminal types, collection granularity marking probability distribution is fitted, local outlier factors are calculated accordingly, a data set conforming to a non-outlier threshold value is screened out, and the data set is subjected to data collection. Then, prior distribution is constructed based on probability distribution, correlation confidence is calculated, a data set with the confidence reaching the standard is screened out, then, a same-granularity feature data set is obtained through merging according to granularity marks, finally, quantitative calibration and correlation analysis are conducted on the data set, and therefore accurate recognition of abnormal software behaviors is achieved.
Owner:CHENGDU QUEYOUQUAN CULTURAL COMMUNICATION CO LTD

Multi-level protocol software dangerous behavior detection method

ActiveCN121859332APlatform integrity maintainanceTemporal logicLinguistic model
The invention belongs to a software dangerous behavior detection technology, and relates to a multilevel protocol software dangerous behavior detection method, which comprises the following steps of: setting a positive and negative example set and a distance measurement function for quantifying the similarity degree of software behavior sequences, and dividing the positive example set into positive example subsets; constructing a tense logic specification weight tree which is a triple composed of a root node weight function and left and right child formula depth weight functions; extracting positive examples from the positive example subsets to form a positive example simplified set; inquiring the large language model to obtain a software dangerous behavior logic formula, and converting the software dangerous behavior logic formula into an equivalent finite state automaton; sampling a counter-example simplified set from the automaton; inquiring the large language model for multiple times based on a positive and negative example simplified set to obtain a formula fragment so as to dynamically update the weight tree and obtain a candidate formula; and selecting the optimal candidate formula as a tense logic specification, and detecting whether the software behavior sequence conforms to the tense logic specification or not. According to the method, the challenges of scarcity of dangerous behavior data and overlarge dangerous behavior search space are relieved.
Owner:SUN YAT SEN UNIV

Software trusted measurement method, device and equipment and computer readable storage medium

The invention discloses a software trusted measurement method, device and equipment and a computer readable storage medium. According to the method, an expected behavior state machine is directly constructed based on a non-interference model, the problems of dependence of dynamic modeling on training data and feasibility of static modeling are fundamentally avoided, and a universal and feasible new software behavior credibility measurement normal form is provided.
Owner:FIBERHOME TELECOMMUNICATION TECHNOLOGIES CO LTD

Software behavior anomaly detection method and device, computer equipment and storage medium

PendingCN121412014AFault responseHardware monitoringAnomaly detectionAlert correlation
The invention belongs to the technical field of software detection, and relates to a software behavior anomaly detection method and device, computer equipment and a storage medium, and the method comprises the steps: determining a monitoring entity and behavior granularity, defining a behavior index, and formulating an evaluation benchmark; according to the determined monitoring entity and the behavior index, original time sequence data and event flow are collected from the level of software and infrastructure; carrying out data preprocessing on the collected time sequence data and the event stream, extracting time sequence characteristics, and carrying out behavior sequence modeling; performing baseline modeling and anomaly detection; performing alarm association and root cause analysis according to an abnormal detection result; and performing response feedback and model optimization according to a root cause analysis result. The problem can be accurately positioned, the detection accuracy is improved, root cause analysis can be assisted, and continuous optimization is realized.
Owner:SHENZHEN EWARE INFORMATION TECH CO LTD