Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

39 results about "Suspicious behaviour" patented technology

Asset vulnerability detection method and device, electronic equipment and storage medium

The invention discloses an asset vulnerability detection method and device, electronic equipment and a storage medium, and relates to the technical field of network security, and the method comprises the steps: actively sending a multi-protocol detection packet to scan a target network segment, and obtaining a first asset set; passively monitoring network traffic to extract asset feature information, and obtaining a second asset set to generate an asset list; port scanning tasks of all assets are dispatched to a plurality of scanning nodes in a distributed and parallel mode, dynamic port scanning is carried out according to a descending order of a plurality of key elements in combination with a port scanning optimization model based on risk prediction, and a full-amount port risk map is constructed; the static layer is matched with known vulnerabilities; the dynamic layer identifies suspicious behaviors deviating from a normal behavior baseline through an anomaly detection algorithm, and obtains an asset vulnerability detection result in combination with a cross validation method; according to the invention, the detection requirements of asset full coverage and early threat discovery in a complex network environment are met.
Owner:GUANGDONG ORIENTAL THOUGHT TECH

Artificial intelligence-driven system and method for orchestrating and automating talent acquisition and HR processes

An artificial intelligence (AI)-driven system and a method for orchestrating and automating a talent acquisition process are disclosed. The AI-driven system comprises a job description generating subsystem, a resume screening subsystem, an interview link generating subsystem, an anomaly detection subsystem, a report generating subsystem, and an autonomous decision-making subsystem. The job description generating subsystem generates precise job descriptions by analyzing hiring needs of organizations The resume screening subsystem evaluates one or more resumes against pre-defined criteria in the job descriptions. The interview link generating subsystem schedules interviews by generating interview links. The anomaly detection subsystem monitors suspicious behaviors of one or more candidates during the interview. The report generating subsystem generates a comprehensive final report that consolidates all aspects of an interview process. The autonomous decision-making subsystem makes decisions at each phase of the talent acquisition process using a cognitive architecture and automatically progresses to subsequent phases.
Owner:ATHMICK INC

Short message fraud early warning method and system based on abnormal behavior detection

The invention discloses a short message fraud early warning method and system based on abnormal behavior detection, and relates to the field of short message fraud early warning, and the method comprises the steps: obtaining user terminal equipment behavior data and financial transaction request behavior data, and constructing a continuous behavior sequence after a user short message is received; constructing a dynamic baseline based on user historical behavior data, calculating a deviation degree between single behavior data and the dynamic baseline, and generating a suspicious behavior set; performing cross-platform behavior tracking to obtain cross-platform behavior data; inputting the deviation degree corresponding to the suspicious behavior, the sequence context information of the occurrence time point of the suspicious behavior and the cross-platform behavior data into an AI fusion analysis model, outputting a fraud risk confidence coefficient, and calculating a fluctuation ratio; and performing fraud behavior identification based on the fraud risk confidence and the fluctuation ratio, and triggering real-time early warning when fraud is confirmed. According to the invention, high-precision and self-adaptive real-time detection and early warning of short message fraud behaviors are realized.
Owner:JIANGSU INTERNET IND MANAGEMENT SERVICE CENT

A computer network monitoring system and method

PendingCN122119926ARealize dynamic perceptionEnable forward-looking assessmentsSecuring communicationNetwork linkAttack
The application provides a computer network monitoring system and method. First, a network security risk graph integrating logical dependencies and vulnerability attributes is constructed, and potential attack chains are deduced and their dynamic risks are evaluated based on the network security risk graph; then, data request sequences of key nodes on the potential attack chains are monitored to identify suspicious behaviors based on dynamic behavior portraits. Then, the identified suspicious behaviors are combined with the dynamic risks of the corresponding attack chains to determine the attack stages of attack activities; finally, based on the determined attack stages, enhanced monitoring is started on related network links and decoy nodes are deployed, and hierarchical alarms are triggered according to attack interaction features captured by the decoy. The above scheme can realize dynamic evaluation and hierarchical response of potential attack chains based on a network security risk graph.
Owner:FUJIAN AGRI VOCATIONAL & TECH COLLEGE

Theft monitoring and identification system for self service point of sale

In an embodiment, the invention provides a theft-monitoring system having one or more cameras, a data store, and a computer processor coupled to the data store and in communication through a network via a web interface with a video reviewer's computing device. The data store includes records that each include collected footage from the cameras and screen or metadata recordings. The processor is programmed, upon receiving an indication of entry of potential purchaser, to track suspicious behavior of the potential purchaser and store data representing screen, video and metadata associated therewith in the data store. The processor determines if the suspicious behavior warrants evaluation, collects relevant data based on the data stored in said data store and, in response to a determination of suspicious activity, transmits the relevant data over a network for review by an operator.
Owner:USCONNECT LLC

An intelligent security and protection system based on high-sensitivity pressure sensor

PendingCN122313657AElectrical connectionSuspicious behaviour
This invention discloses an intelligent security system based on a high-sensitivity pressure sensor, comprising a sensing module, a signal processing module, a data transmission module, a control module, an alarm module, and a power supply module. These modules are electrically connected sequentially, and the power supply module provides operating voltage to the other modules. The system employs high-sensitivity and multi-fusion technologies to achieve rapid and efficient security system construction. It utilizes a high-sensitivity pressure sensor as the sensing device to quickly detect suspicious behavior and issue real-time alarms; it uses artificial intelligence video analysis technology to judge suspicious objects; and its signal processing employs domestically produced chips, a remote terminal with a database, and a system fusion platform to ensure information security, high-performance processing of alarm information, and to provide alarm signals to other security and fire protection systems for system linkage.
Owner:TIANJIN 2D TECH CO LTD

POS system and POS system operation method

This enables efficient detection and appropriate suppression of suspected shoplifting incidents. [Solution] The POS system 100 includes a sensor 106 that observes predetermined events related to customers in a store, a processor 104 that performs a process of applying the observation results obtained from the sensor 106 to an algorithm 112 for detecting suspicious behavior to detect suspicious behavior by the customer, and a process of notifying at least one of the store staff or the customer of the detection result or a predetermined notification content corresponding to the result.
Owner:株式会社ヴィンクス

Dashcam Network with Route Logging and Computer Vision for Targeted Video Search Capabilities

PendingUS20260141557A1Image enhancementImage analysisEngineeringSuspicious behaviour
The present invention discloses a system to assist investigations for storage and targeted search of metadata and video collected by dashcams. The invention efficiently guides video evidence search using stored route metadata versus complete footage, tackling the challenges of distributed footage across vehicles. The system enhances investigations by unlocking previously inaccessible visual evidence in a targeted manner while optimizing storage and bandwidth. Vehicles equipped with cameras send real-time route metadata and / or video to the system. This data may include coordinates, timestamps, license plates detected, facial features, street names, addresses, suspicious behavior data, and other details related to the route. Investigators may input search parameters related to location, timing, vehicles, objects, persons, etc. Computer vision algorithms analyze stored metadata to identify matching routes and footage. Investigators may access the video from central storage or, if only metadata about the route was submitted, request relevant footage from the respective driver.
Owner:OWENS NICHOLAS DEMES

System and method for preventing and mitigating malicious processes by analyzing live data

A system (100) or method (500) for preventing or mitigating malicious processes in a computing environment having one or more processors (204) and memory (202) operatively coupled to the one or more processors can include computer instructions which when executed causes the one or more processors to perform certain operations. The operations can include intercepting (502) all file system input and output paths using a kernel driver (103), analyzing (504) for suspect behaviors in real time on data being processed through the input and output paths and data access patterns on a live system implemented in a kernel of an operating system for the computing environment, flagging (512) the data for any suspect behaviors, and preventing (514) further processing upon detection of the suspect behaviors.
Owner:THALES DIS CPL USA INC

Network attack processing method, system and device, storage medium and program product

PendingCN121530601ABiological modelsSecuring communicationAttackSuspicious behaviour
The embodiment of the invention provides a network attack processing method, system and device, a storage medium and a program product. In the process of performing security protection on the target host, when a suspicious behavior on the target host is detected, behavior data corresponding to the suspicious behavior can be obtained, an interception rule corresponding to the suspicious behavior is obtained according to the behavior data, and the interception rule is determined by using an attack analysis model. The attack analysis model is obtained by training the behavior data sample of the process corresponding to the historical network attack behavior, so that the attack analysis model can better master the knowledge of the network attack field. When the behavior data of the process with the suspicious behavior is analyzed, the attack analysis model can identify and judge the behavior of the process more accurately, so that an interception rule with higher confrontation is generated. Therefore, the potential security threats corresponding to the suspicious behaviors can be quickly and accurately processed, the risk of missing potential attacks is reduced, and the defense capability is improved.
Owner:ALIBABA CLOUD COMPUTING CO LTD

Abnormal behavior detection method, terminal equipment and storage medium

PendingCN121883932AImage enhancementImage analysisTerminal equipmentSuspicious behaviour
The invention discloses an abnormal behavior detection method, terminal equipment and a storage medium. The method comprises the following steps: acquiring a video stream of a target scene in a current time period; tracking the motion trail of each target in the video stream; for each target, determining that the target is a suspicious target under the condition of determining that the target has suspicious behaviors in the current time period according to the movement track of the target; according to the motion trail of the suspicious target and the video stream, identifying the behavior intention of the suspicious target in the current time period to obtain a behavior intention identification result; and determining whether the suspicious target has an abnormal behavior or not according to the behavior intention recognition result. According to the scheme, the normal interaction behavior and the malicious heuristic behavior of the target can be effectively distinguished, and the accuracy of abnormal behavior detection is remarkably improved.
Owner:SHENZHEN INTELLIFUSION TECHNOLOGIES CO LTD

Artificial intelligence-driven system and method for orchestrating and automating talent acquisition and HR processes

An artificial intelligence (AI)-driven system and a method for orchestrating and automating a talent acquisition process are disclosed. The AI-driven system comprises a job description generating subsystem, a resume screening subsystem, an interview link generating subsystem, an anomaly detection subsystem, a report generating subsystem, and an autonomous decision-making subsystem. The job description generating subsystem generates precise job descriptions by analyzing hiring needs of organizations. The resume screening subsystem evaluates one or more resumes against pre-defined criteria in the job descriptions. The interview link generating subsystem schedules interviews by generating interview links. The anomaly detection subsystem monitors suspicious behaviors of one or more candidates during the interview. The report generating subsystem generates a comprehensive final report that consolidates all aspects of an interview process. The autonomous decision-making subsystem makes decisions at each phase of the talent acquisition process using a cognitive architecture and automatically progresses to subsequent phases.
Owner:ATHMICK INC

Financial account abnormity identification method and device, equipment, medium and program product

PendingCN121834594AFinanceKnowledge representationMulti source dataSuspicious behaviour
The invention relates to a financial account abnormity identification method and device, equipment, a medium and a program product. The method comprises the following steps: acquiring multi-source data of a newly added abnormal account; identifying a suspicious behavior pattern from the multi-source data, and generating a candidate identification rule based on the suspicious behavior pattern; performing similarity comparison on the candidate recognition rule and each recognition rule to obtain a similarity index; if each similarity index is smaller than a similarity threshold value, testing the candidate recognition rule based on the historical account behavior set to obtain a preset test index; if the preset test index meets the condition, adding the candidate identification rule into a current identification rule base; and in response to the received target financial account behavior data, performing anomaly identification on the target financial account behavior data based on the latest identification rule library of the rule engine. By adopting the method, the new recognition rule can be automatically and efficiently learned from the abnormal data, the problems that the recognition rule depends on manual summarization, updating lags and the like are avoided, and the anomaly recognition timeliness and the intelligence level are improved.
Owner:CHINA CONSTRUCTION BANK +1

Video anti-theft early warning method based on target tracking and related equipment

The invention relates to the technical field of target tracking, and discloses a video anti-theft early warning method based on target tracking and related equipment, and the method comprises the steps: carrying out the imaging enhancement of an original video frame collected by a wireless intelligent doorbell in a low-light environment, and obtaining a low-light enhanced video sequence; performing time sequence consistency constraint depth estimation based on the low light enhancement video sequence to obtain a target depth distribution map and constructing a dynamic target tracking map; performing double-layer boundary constraint analysis based on the dynamic target tracking graph to obtain a target tracking trajectory; and calculating a comprehensive suspicious behavior score based on the target tracking trajectory and generating a doorbell alarm signal. The method can effectively capture an interaction mode and long-time behavior characteristics between targets, directly embed physical constraints into a target tracking process, realize accurate distinguishing of normal visitors and potential threats, and effectively reduce a false alarm rate.
Owner:SHENZHEN SHENAN YANGGUANG ELECTRONICS CO LTD

Cyber attack processing method and system, device, storage medium, and program product

Embodiments of the present disclosure provide a cyber attack processing method and system, a device, a storage medium, and a program product. In the process of performing security protection on a target host, when a suspicious behavior on the target host is detected, behavior data corresponding to the suspicious behavior may be acquired, and an interception rule corresponding to the suspicious behavior is acquired on the basis of the behavior data, wherein the interception rule is determined by using an attack analysis model. The attack analysis model is obtained by training behavior data samples of processes corresponding to historical cyber attack behaviors, and therefore, the attack analysis model can better grasp knowledge in the field of cyber attacks. When analyzing behavior data of a process of the suspicious behavior, the attack analysis model can more accurately identify and determine the behavior of the process, thereby generating a more adversarial interception rule. Therefore, it is convenient to quickly and accurately process potential security threats corresponding to suspicious behaviors, the risk of missing potential attacks is reduced, and the defensive capability is improved.
Owner:CLOUD INTELLIGENCE ASSETS HOLDING (SINGAPORE) PTE LTD +1

A security identification method and system based on intelligent AI

This invention relates to the field of intelligent security identification technology, and discloses an intelligent AI-based security identification method and system. The method collects historical data on abnormal behavior to establish a standard behavior model library; after collecting real-time monitoring datasets, it determines the security scanning interval based on the data scale; within the scanning interval, it acquires all monitoring signals and calculates the average feature value as a security judgment benchmark; based on the benchmark and the standard model library, it evaluates the monitoring signals, identifies and labels suspicious abnormal behaviors. When suspicious behavior exists, its parameter attributes and behavioral pattern features are extracted to determine whether it is a real threat behavior, and then a basic risk value is determined based on the frequency of threat occurrence. Subsequently, the behavioral sequences, operation types, and interaction trajectories of real threats are analyzed, and the trajectories are used as feature vectors for classification analysis using a classification algorithm to determine whether there are associated attack patterns; if so, a correction factor is calculated to update the basic risk value, and the next security scanning interval is reconfigured.
Owner:GUANGDONG QIMING INFORMATION TECHNOLOGY CO LTD

Information processing device, information processing method, and program

This invention provides an information processing device, an information processing method, and a program that improve the accuracy of person recognition. [Solution] An information processing device 100 that verifies the identity of a registered person by facial recognition when payment is made at an unmanned checkout counter in a store, comprising: an action detection unit 303 that detects suspicious behavior of a person detected from an image; a biometric recognition unit 310 that performs recognition processing on the detected person based on biometric information obtained from the image of the detected person; and a level change unit 306 that changes the security level related to the recognition processing by the biometric recognition unit 310 based on the detected suspicious behavior.
Owner:CANON KK

Suspicious behavior identification early warning management system based on big data analysis

The invention discloses a suspicious behavior recognition early warning management system based on big data analysis, and the system comprises a service recognition module which is used for outputting an analysis parameter feature vector matched with a service type based on the asset information accessed by a user, outputting an intention type and an intention consistency score based on a search query word of the user, and outputting an analysis parameter feature vector matched with the service type; based on the user login time, the equipment type and the geographic position, constructing a spatio-temporal feature vector; the behavior sequence analysis module is connected to perform semantic and differentiated sequence anomaly recognition, generate an offset sequence feature signal, and generate a dynamic baseline of time period perception and equipment type perception according to the spatio-temporal feature vector; the behavior frequency analysis module generates a frequency mutation characteristic quantity; the sensitive grading judgment module calculates the grading sensitive weight of the assets; and the notification content push module dynamically matches a push object and optimizes the structure and hierarchy of the early warning information based on the hierarchical sensitive weight, and generates and sends role early warning push information.
Owner:DEZHOU UNIV

Digital twins for monitoring server attacks in federated learning environments

A digital twin is intertwined with a central server and configured to generate acceptability distributions based on updates received from clients at the server in the federated learning system. The acceptability distributions, which may account for the probability of transmission failures, are used to identify anomalous behaviors, including anomalies in global gradient updates, server attacks and / or suspicious behavior.
Owner:DELL PROD LP

Fully local security behavior analysis and ai device and method

To solve the problem that it is difficult to perform real-time analysis in an offline environment or outdoors since a conventional crime prevention system has a communication delay and a privacy leakage risk due to cloud dependence.SOLUTION: In the present invention, a camera video is input, a person or an object is extracted by an arbitrary object detection means, a posture / action feature is estimated by a motion analysis means, and a suspicious action is determined by a machine learning model. The determination result is output as a warning by the speech synthesis, and displayed and recorded on the GUI in real time. To achieve high-speed and safe crime prevention action analysis which is portable by mobile battery drive and does not go through a cloud.
Owner:松尾 信慎

System

PendingJP2026024191AOffice automationPlatform integrity maintainanceActivity monitorSuspicious behaviour
An object of a system according to an embodiment is to detect a suspicious behavior of an employee in real time and to quickly cope with the suspicious behavior.SOLUTION: A system according to an embodiment includes an activity monitoring unit, a suspicious action detection unit, a warning transmission unit, and a countermeasure proposal unit. The activity monitoring unit monitors the activity of the employee in real time. The suspicious behavior detection unit detects suspicious behavior from the activity monitored by the activity monitoring unit. The warning sending unit sends a warning based on the abnormality detected by the suspicious action detection unit. The countermeasure proposal unit proposes an appropriate countermeasure based on the warning transmitted by the warning transmission unit.SELECTED DRAWING: Figure 1
Owner:SOFTBANK GROUP CORP

Process abnormal behavior detection method based on semantics

The invention relates to a process abnormal behavior detection method based on semanteme, and belongs to the field of process abnormal behavior detection.The method comprises the steps that process operation data in a host is collected, and field standardization is conducted on the process operation data; performing semantic feature extraction on the standardized process operation data according to a designed semantic feature algorithm to realize vectorization of text data, and training to obtain a single record detection model and a multi-record detection model according to vectorized data obtained after processing; detecting the feature vector by adopting the single record detection model to obtain the malicious degree of the single record; and collecting a plurality of operation records related to the suspicious behavior record according to the malicious degree of the single record, processing the operation records into a to-be-detected sample set, then performing secondary detection on the to-be-detected sample set by a multi-record detection model, and giving an alarm for a behavior sequence with a detection result being malicious. The method provided by the invention can effectively improve the detection rate and reduce the false alarm rate.
Owner:北京国御网络安全技术有限公司

Fund flow automatic marking and suspicious behavior identification method based on semantic enhancement

The invention relates to the technical field of financial data, in particular to a fund flow automatic marking and suspicious behavior recognition method based on semantic enhancement, comprising the following steps: S1, multi-stage data preprocessing and preliminary marking: receiving an original fund flow file uploaded by a user, and calling a data governance service to execute field cleaning, format standardization and entity alignment operations on the original fund pipeline data, and performing preliminary classification on the cleaned data based on a predefined business rule base. According to the invention, the defect of insufficient hidden suspicious behavior identification capability of a traditional method is overcome; the technical threshold of case handling personnel is greatly reduced through interactive analysis, the report generation efficiency is improved by more than 5 times, and the working efficiency is remarkably improved; the whole system supports rapid deployment in scenes of financial supervision, public security investigation, discipline inspection and supervision and the like, can effectively prevent financial risks and fight against illegal and criminal activities, and has remarkable social benefits and commercial values.
Owner:ZHIQIYUN NAJING INFORMATION TECH CO LTD

Examination room abnormal behavior identification method and device and computer equipment

The invention relates to an examination room abnormal behavior identification method and device and computer equipment. The method comprises the following steps: acquiring a current monitoring video monitored in an examination room, and identifying an examination room desktop detection matrix through a perspective transformation strategy based on a first frame image in the current monitoring video; based on the examination room desktop detection matrix, through a range correction strategy, generating an examinee bit sequence matrix, and based on the examinee bit sequence matrix and the current monitoring video, through an examinee target tracking strategy, generating examinee behavior track information of each examinee; and on the basis of the examinee behavior track information of each examinee, through a dynamic behavior analysis strategy, identifying examinee abnormal behavior information of each examinee. By adopting the method, the monitoring accuracy of the suspicious behaviors in the examination room can be improved.
Owner:兰州乐智教育科技有限责任公司

A call detection method and system based on multi-modal feature fusion

The application relates to the technical field of communication security, in particular to a call detection method and system based on multi-modal feature fusion, which comprises the following steps: collecting voice signals, video signals and / or communication metadata in real time during a call process of a first communication party and a second communication party; in a first target scene, obtaining a voice signal stream corresponding to the voice signals, a video signal stream corresponding to the video signals and recently collected communication metadata; the first target scene refers to an abnormal call scene with risks determined based on voice keywords; performing feature extraction and feature fusion on the voice signal stream, the video signal stream and the recently collected communication metadata to obtain multi-modal features; and inputting the multi-modal features into a deep learning model to obtain suspicious behavior detection results. It can be seen that the method can realize real-time and accurate detection of suspicious behaviors in calls through multi-modal data fusion, effectively make up for the limitations of single-modal detection, and has high identification timeliness and accuracy.
Owner:ULTRAPOWER SOFTWARE

System

An object of a system according to an embodiment is to efficiently detect malware on a server and quickly take measures.SOLUTION: A system according to an embodiment includes a scanning unit, a learning unit, and a countermeasure unit. The scan unit includes a generation AI. The learning unit learns characteristics of suspicious behavior and malware based on data of files and programs of the server scanned by the scanning unit. The countermeasure unit detects malware based on the feature learned by the learning unit, and takes a countermeasure.SELECTED DRAWING: Figure 1
Owner:SOFTBANK GROUP CORP

Inter-unit devices and suspicious behavior detection systems

PendingJP2026137310AHand partsImaging analysis
The system will be able to appropriately detect and notify of acts of vandalism targeting multiple parts of gaming machines and inter-machine devices. [Solution] The system is equipped with an imaging unit 111, and an image analysis unit 112 analyzes the image captured by the imaging unit 111 to identify the location of the player's hand. When the image analysis unit 112 detects that the player's hand is located in one or more locations, the operation log acquisition unit 113 acquires operation log information. The suspicious behavior detection unit 114 detects the occurrence of suspicious behavior if the operation log acquisition unit 113 could not acquire operation log information related to the location of the player's hand identified by the image analysis unit 112. When the suspicious behavior detection unit 114 detects the occurrence of suspicious behavior, it notifies the user of the occurrence of suspicious behavior through a notification means such as a display unit 109.
Owner:SAXA

Early warning method and device based on anti-terrorism riot abnormality detection

The application discloses an early warning method and device based on anti-terrorism and riot abnormality detection. The application comprises the following steps: acquiring multi-source situation data of a detection task area, using video stream data in the multi-source situation data to detect a weapon-carrying target, and obtaining a weapon-carrying target screening result; using picture frame data in the multi-source situation data to detect suspicious behavior, and obtaining a behavior-suspected target screening result; using target space-time trajectory data in the multi-source situation data to detect a target yawing trajectory, and obtaining a yawing target screening result; judging a threat level of the detection task area based on the weapon-carrying target screening result, the behavior-suspected target screening result and the yawing target screening result, and performing early warning based on the threat level. The application utilizes multi-source situation data to form complementation, more comprehensively masters suspicious target movement, realizes real-time sensing of a scene situation, and improves crisis response and disposal capability in anti-terrorism and riot decision-making.
Owner:BEIJING INST OF TECH

Network security dynamic protection method

The invention discloses a network security dynamic protection method, and belongs to the technical field of network security dynamic protection. The method comprises the following steps: monitoring a network access request of a target system, identifying a suspicious behavior pattern of the network access request, and generating a dynamic interaction response; guiding an access subject initiating the network access request to a virtual protection environment through the dynamic interaction response; and in the virtual protection environment, collecting depth behavior data of the access subject, and updating a global protection strategy of the target system according to the depth behavior data. Meanwhile, the depth behavior data serve as a training sample to train a preset behavior prediction model, the trained behavior prediction model is utilized to predict potential attack behaviors, and matched virtual protection environment resources are pre-configured. According to the method, active trapping and deep analysis of attack behaviors are realized, the initiative and dynamic adaptability of system protection are improved, and the perspectiveness of resource scheduling is enhanced.
Owner:HUANENG INFORMATION TECH CO LTD