Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

235 results about "Syslog" patented technology

In computing, syslog /ˈsɪslɒɡ/ is a standard for message logging. It allows separation of the software that generates messages, the system that stores them, and the software that reports and analyzes them. Each message is labeled with a facility code, indicating the software type generating the message, and assigned a severity level.

AI data warehouse full-link consanguinity tracking method and AI data warehouse full-link consanguinity tracking device

The invention discloses an AI data warehouse full-link blood relationship tracking method and device, and relates to the technical field of data processing. The method comprises the following steps: obtaining structured log data with business terms and entity tags; establishing a knowledge graph according to the structured log data and the business document; generating blood relationship metadata according to the knowledge graph and the data job execution log; constructing a blood relationship cognition map according to the blood relationship metadata, the data operation log and the business document; generating a governance strategy vector according to the blood relationship cognitive map, the system real-time index and the service SLO, and sending the governance strategy vector to an execution engine, so that the execution engine carries out processing according to the governance strategy vector; and obtaining a governance strategy execution result, user feedback information of the governance strategy execution result and a system log generated in a governance process. According to the method, complex semantics and causal relationships behind data operation can be captured.
Owner:BEIJING GZT NETWORK TECH

Network information security monitoring system

The invention relates to the technical field of information security, and discloses a network information security monitoring system, which comprises the following modules: a data collection module used for collecting data from network traffic, system logs and user behaviors in real time; the data processing module adopts a Z-score standardized processing technology to unify different features to the same scale so as to ensure that the mean value of the features is 0 and the standard deviation is 1, thereby improving the comparability between the features; and the threat detection module analyzes the processed data based on a machine learning algorithm and identifies possible network security threats. Through cooperative work of all the modules, comprehensive real-time data collection, accurate threat detection, practical response execution and continuous feedback optimization are realized, the network security threat handling capacity is integrally improved, and network information security monitoring work is stably and efficiently carried out for a long time. The problem that a response strategy of a traditional network information security monitoring system lacks pertinence and timeliness is solved.
Owner:WUHAN DINGCHENG WEIDU TECHNOLOGY CO LTD

A centralized computer network traffic monitoring and intrusion detection system for a computer network

A centralized network traffic monitoring and intrusion detection system (1) comprising a system log aggregation module (110) including a means for receiving (111), a means for decoding (112) the user's syslog, a means for comparing (113) the data from the means for decoding, and a means for indexing (114) the tagged data and storing the indexed data. The system (1) also comprises an analysis and alert module (120) including a means for fetching (121) the indexed data, a means for checking and correlating (122) the retrieved indexed data, a means for analysing (123) the checked and correlated data, a means for compiling (124) the analysed and prioritized data and generating a report, and a means for alerting (124). The system (1) further includes a Bad IP Feed module (130) including a means for generating (131) updated lists of bad IP addresses and hostnames and automatically updating a user's network devices.
Owner:E LOCK CORP

Network security detection method based on artificial intelligence

The invention belongs to the technical field of network security, and particularly relates to a network security detection method based on artificial intelligence, which comprises the following steps of: acquiring network flow data, system log data, user behavior data and external threat intelligence data, generating a multi-source heterogeneous data set, preprocessing the multi-source heterogeneous data set, and acquiring a multi-source heterogeneous data set; comprising the steps of data normalization, missing value filling and noise filtering, feature extraction is conducted on preprocessed data through a multi-modal fusion model, extracted multi-modal features are input into a mixed detection engine, the detection rate of zero-day attacks can be increased to a high level through multi-modal data fusion, and compared with the prior art, the detection rate of zero-day attacks is increased. The detection rate of a traditional method has obvious advantages in the aspect of coping with novel threats, and meanwhile, the false alarm rate can be reduced below a normal value in the aspect of false alarm rate control, so that the burden of safety personnel for handling invalid alarms is greatly reduced, and the situation that a large number of false alarms cause waste of manpower and material resources and possibly cause the fact that real safety threats are neglected is avoided.
Owner:王允昕

Network security monitoring method and system based on computing power, and electronic equipment

The invention relates to the technical field of network security monitoring scheme design based on computing power, in particular to a network security monitoring method and system based on computing power and electronic equipment. The method comprises the following steps: collecting network traffic, system logs and user behavior data; dynamically distributing CPU / GPU computing power according to network flow, attack frequency and the like; performing cleaning and format conversion on the data; intrusion detection, vulnerability scanning and traffic anomaly analysis are executed through multi-task parallel processing; a potential attack mode is mined in combination with deep learning model and rule engine association analysis; and judging threats according to a preset rule base and triggering early warning. According to the method, the resource utilization rate is improved through intelligent computing power scheduling, the threat recognition capability is enhanced in combination with deep learning and rule double engines, the method can adapt to a complex network environment, the threat detection accuracy is 98.7% according to actual measurement display, the resource occupation is reduced by 30%, and the method is suitable for high-concurrency scenes such as a cloud platform and the Internet of Things.
Owner:SHANGHAI QINSHANSONG TECHNOLOGY CO LTD

Network traffic anomaly real-time detection method based on deep learning

The invention relates to the technical field of network flow detection, in particular to a real-time network flow anomaly detection method based on deep learning, and the system comprises the following steps: S1, carrying out the real-time collection and preprocessing of multi-modal data; s2, performing dynamic feature engineering and sliding window statistics; s3, carrying out online adaptive threshold initialization; s4, multi-modal deep learning model reasoning is carried out; s5, updating the adaptive threshold in real time; s6, abnormal decision making and confidence coefficient calibration; s7, generating interpretability analysis; and S8, performing real-time feedback and online learning. According to the scheme, the capability of detecting hidden and complex attacks is remarkably improved through multi-modal data fusion and dynamic feature engineering, network traffic, system logs, user behavior data and external threat intelligence are synchronously collected, and traffic statistical features, time sequence change features, frequency domain features and distribution features are extracted in real time by using a sliding window mechanism.
Owner:WUXI YUANSHUCHENG TECHNOLOGY CO LTD

Module identification method and device based on hybrid detection mechanism and storage medium

The invention discloses a module identification method and device based on a hybrid detection mechanism, and a storage medium, relates to the technical field of device management, and discloses a module identification method based on the hybrid detection mechanism, and the method comprises the steps: scanning a preset interface to obtain current equipment node information after a system is powered on, analyzing the system log to extract equipment event information; generating an initial module list based on the equipment node information and the equipment event information; in response to the hot plug event, executing the same scanning and system log analysis operation when the system is powered on, and obtaining a compensation scanning result; and generating an updated module list according to the initial module list and the compensation scanning result. Through a hybrid detection mechanism combining static scanning and dynamic event driving, the accuracy and real-time performance of module identification are effectively improved, system start initialization and operation period hot plug scenes are considered, and the problem of state inconsistency caused by event loss or equipment residue is avoided.
Owner:SHENZHEN SHENBAO ELECTRONIC METER CO LTD

Automatic UI function test method and system, electronic equipment and storage medium

The invention relates to the technical field of software development, and discloses an automatic UI function test method and system, electronic equipment and a storage medium. The method comprises the steps of receiving a natural language test requirement; intercepting an interface image in real time and transmitting the interface image to a multi-modal analysis module through an API; interface element layout is identified based on computer vision (CV), demand semantics are analyzed in combination with natural language processing (NLP), and a dynamic operation instruction set is generated; driving the automatic tool to execute clicking, sliding and input operations through the API; dynamically adjusting a test path according to execution feedback, and covering a multi-scene case; interface element states, system logs and performance data are monitored in real time, and automatic verification is achieved through multi-dimensional data comparison. According to the method, multi-modal recognition and AI intention understanding technologies are fused, the problems that a traditional UI test script is high in maintenance cost and low in scene coverage rate are solved, non-intrusive self-adaptive full-process testing is achieved, and the testing efficiency is improved by 40% or above.
Owner:SHANGHAI TEND INFORMATION TECH CO LTD

Multi-source data fusion IT operation and maintenance fault root cause analysis method and system

The invention discloses a multi-source data fusion IT operation and maintenance fault root cause analysis method, which comprises the following steps: data acquisition: acquiring data in real time from a plurality of data sources in an IT system, the data sources specifically being system logs, performance index data and network topology data, and the data sources being data of the IT system; the data acquisition is carried out according to a preset time interval or an event triggering mechanism; data preprocessing: preprocessing the multi-source data collected in the step S10, specifically comprising: a data cleaning step: removing noise, repeated data and incomplete data in the data; in the data conversion step, data in different formats are converted into data in a unified structured format, and in the data normalization step, a minimum-maximum normalization method is adopted. The multi-source data fusion IT operation and maintenance fault root cause analysis method and system aim to realize rapid and accurate identification of IT operation and maintenance fault root causes by fusing multiple data sources and utilizing an advanced data analysis technology.
Owner:SHANGHAI NEW CENTURION NETWORK INFORMATION TECH CO LTD

Apparatuses for audit data generation and verification

It is provided an apparatus comprising interface circuitry, machine-readable instructions, and processing circuitry to execute the machine-readable instructions. The machine-readable instructions include instructions to receive data from a remote entity for handling by a computing system. The machine-readable instructions further include instructions to instantiate a first TEE and a second TEE. The machine-readable instructions further include instructions to generate log data corresponding to predefined activities of the computing system and to generate system record data of a system log of the computing system at predetermined times. The machine-readable instructions further include instructions to generate first audit data by the first TEE and second audit data by the second TEE. The machine-readable instructions further include instructions to transmit the first and the second audit data to a detection system for data aggregation and anomaly detection.
Owner:VAUGHN ROBERT +4

AI-powered system for detecting and preventing data breaches

AI-powered data breach detection and prevention system that includes: a threat monitoring module for continuous analysis of network traffic, system logs and user activities; an AI-powered anomaly detection module that uses machine learning to detect threats, including zero-day attacks and insider threats; a behavioral analysis module that tracks user authentication, access patterns, and privilege escalations; an automated incident response module that isolates threats, blocks unauthorized access, and alerts security teams; a threat intelligence module that integrates global cybersecurity databases for proactive risk mitigation; a multi-layered security system with endpoint protection, encryption and role-based access control; a privacy-preserving mechanism that uses homomorphic encryption and federated learning to protect sensitive data; a compliance and audit module that ensures compliance with cybersecurity regulations.
Owner:MURALINATHAN SRINATH UNION CITY

Single machine room fault recovery laas cluster processing system

The invention relates to the technical field of cloud computing and server hosting technology, and discloses a single machine room fault recovery laas cluster processing system, comprising a fault detection module which is responsible for monitoring the health state of each node in a cluster in real time, analyzing system logs and performance indexes, and quickly identifying potential faults; the fault evaluation module is used for receiving the output of the fault detection module, evaluating a fault influence range and severity and providing a basis for a fault recovery strategy; the resource scheduling module is used for dynamically adjusting resource allocation according to a fault assessment result and selecting an optimal healthy node for service migration; and the service migration module is responsible for smoothly migrating the service on the fault node to the healthy node, and reducing the service interruption time by adopting a live migration technology. The invention provides a single-computer-room fault recovery laas cluster processing system, and solves the problems that a cluster processing system in the prior art is high in single-point fault risk, delayed in fault detection response, inflexible in resource scheduling and insufficient in cross-computer-room cooperative capability.
Owner:GUANGXI POWER GRID CORP

Network security intelligent monitoring method and system, and electronic equipment

The invention relates to the technical field of network security intelligent monitoring scheme design, in particular to a network security intelligent monitoring method and system and electronic equipment. Comprising the steps that firstly, data are collected from multiple data sources of a network, network flow data, system log data, application program log data and the like are covered, and deep features are extracted through a deep learning algorithm; and then, an integrated learning behavior analysis model based on machine learning is adopted to analyze the preprocessed data, and by monitoring an analysis result in real time, decision making is carried out according to the type and severity of the abnormal behavior in combination with a predefined strategy, such as alarming, connection blocking or access permission adjustment. In addition, the system can continuously monitor network environment changes and automatically adjust parameters of the behavior analysis model. Through multi-aspect improvement, the false alarm rate is remarkably reduced, the data processing efficiency is improved, the monitoring system can adapt to the network environment change, and the accuracy and reliability of network security monitoring are effectively improved.
Owner:HUBEI POLYTECHNIC UNIV

Transmission data compression method and system based on cloud computing

The invention relates to the technical field of electric digital data processing, and provides a transmission data compression method and system based on cloud computing, and the method comprises the steps: collecting system log data, obtaining a to-be-compressed character string and a to-be-compressed character string set, obtaining a high-frequency code according to the to-be-compressed character string set, and calculating the global redundancy high frequency of the to-be-compressed character string; according to the global redundancy high frequency and the high frequency code of the to-be-compressed character string, the redundancy matching density and the global compression gain degree of the to-be-compressed character string are obtained, then the to-be-compressed character string is subjected to global compression according to the global compression gain degree of the to-be-compressed character string, and then the global compression character string is compressed by using an LZ77 compression algorithm. And then transmission of the system log data is completed. The method aims at solving the problems that an existing LZ77 compression algorithm only considers local similarity, and the compression efficiency of system log data with high global repeatability is not high enough.
Owner:SHENZHEN ENCYCLOPEDIA ZHIYUN TECHNOLOGY CO LTD

Server fault prediction method, device and equipment based on multiple modes

The invention provides a server fault prediction method, device and equipment based on multiple modes, which are applied to the technical field of fault prediction, and the method comprises the following steps: collecting multi-mode data of a node server; the multi-modal data includes at least two of thermograms, system logs, GPU utilization, power consumption, temperature, fan speed and fan audio. And respectively extracting a modal feature corresponding to each modal from the multi-modal data. And fusing modal features of all modals in the multi-modal data, and predicting fault information of the node server. And mapping the fault information to the thermogram to obtain a fault risk map of the node server. The fault risk map is used for displaying the fault information in the thermogram in an overlapping manner. The problem that a traditional fault prediction method based on a single data source is difficult to discover hidden problems generated by a server, so that the fault of the server cannot be predicted in time can be solved.
Owner:ZHEJIANG DETACENT DATA TECH CO LTD +1

Log processing method and device, medium and product

The invention discloses a log processing method and device, a medium and a product, relates to the technical field of distributed system log management, and can be applied to the field of financial science and technology. The method comprises the following steps: sending a receiving node query request to a policy service, so that the policy service determines a target receiving node according to the receiving node query request; obtaining a target receiving node fed back by the policy service; based on the local system portrait model, processing the current system index data to obtain a business trough period window; determining an estimated transmission time length and a recommended transmission time period according to the data volume and the current available bandwidth of the to-be-transmitted log file and the service trough period window; sending a transmission decision request to a policy service; obtaining a target transmission time period and a fragment sequence fed back by the policy service; and transmitting a fragment sequence to the server through the target receiving node based on the target transmission time period, the fragment sequence comprising at least one log fragment. Through the technical scheme, the log processing efficiency can be improved.
Owner:INDUSTRIAL AND COMMERCIAL BANK OF CHINA

System log detection method and device based on spiking neural network and storage medium

The invention belongs to the technical field of distributed system management and maintenance, and discloses a system log detection method and device based on a spiking neural network and a storage medium, and the method comprises the steps: achieving the semantic embedding of each log in a log sequence through a pre-training T5 model, and obtaining a word embedding sequence of context semantic association; then, pulse feature coding is carried out on the log semantic information to capture semantic information and time dynamic in the embedded words, and therefore effective packaging of log semantics and time information can be achieved, and a space-time pulse sequence is obtained; and finally, inputting the pulse sequence into the trained pulse neural network model to obtain a log anomaly detection result. Therefore, the time and semantic information of the logs can be effectively packaged, and meanwhile, the association relationship between the logs is captured by virtue of the T5 model and the spiking neural network model, so that the anomaly detection of the logs based on log association and time sensitivity is realized; in this way, the effectiveness and accuracy of log anomaly detection are improved.
Owner:CHENGDU TECH UNIV +1

Network information security early warning system based on big data analysis

The invention relates to the technical field of network information security, in particular to a network information security early warning system based on big data analysis, which comprises a data acquisition and processing module used for acquiring network flow data, system log data and user behavior data in real time and performing cleaning, normalization and feature extraction on the acquired data; and the big data intelligent analysis module is used for detecting logic bombs in the system through a big data analysis technology, blocking a remote control bypass in the system, identifying illegal communication behaviors in the system and defending a greedy program in the system, and generating a report. Through omnibearing acquisition and deep analysis of mass data generated by system operation, hidden logic bombs are accurately recognized, hidden dangers are eliminated in advance, once remote control bypass communication is found, blocking measures are immediately taken, it is ensured that the system control right is not illegally captured, illegal behaviors hidden in normal communication can be accurately recognized, and the safety of remote control bypass communication is ensured. And the security of sensitive information is effectively protected.
Owner:SHENZHEN ZHONGGANG LIANYING IND CO LTD

Block chain power abnormal data tracing method

The invention relates to the technical field of computers, in particular to a block chain power abnormal data tracing method. The method comprises the following steps: acquiring operation data and system logs of a power system, extracting model input, identifying exceptions and completing event source classification; for the abnormal generation differential change records, timestamps are extracted to construct chain records, and the chain records are serialized into traceable paths; performing cross-source alignment and sequence correction to form a consistent event sequence, classifying and sorting to obtain an event sequence structure, and verifying to generate a cross-system traceability path; and finally verifying a conclusion through a consensus mechanism, extracting a traceability report, and updating the anomaly detection model according to the traceability report. According to the method, the cross-source time sequence consistency and the evidence playback performance are improved, the conclusion credibility and the closed-loop iteration capability are enhanced, and the method is suitable for scenes such as data metering and equipment monitoring.
Owner:BEIJING FIBO XINDA TECHNOLOGY CO LTD

Log processing method and device

The invention discloses a log processing method, and the method can obtain an alarm result through processed system log data and related log data, matches an alarm rule based on semantic similarity, effectively reduces the false alarm and missing alarm, and improves the alarm accuracy. And a comprehensive and accurate alarm result is generated in combination with historical logs and context information, so that operation and maintenance personnel are assisted to quickly position faults. The log processing efficiency is greatly improved and the real-time requirement of large-scale data is met by utilizing efficient indexing and searching capability and by means of data vector rapid retrieval; an alarm rule and an embedded model are optimized according to user feedback, the manual maintenance workload is reduced, and the operation and maintenance cost is reduced; complex systems and variable service scenes can be processed, and different types of log data and alarm requirements can be met; different from completely depending on a large-scale pre-training model, the related log data is determined by using the data vector corresponding to the processed system log data, and the alarm rule is judged, so that computing resources are utilized more efficiently, and the system operation cost is reduced.
Owner:YUANYU INFORMATION TECHNOLOGY (SHANGHAI) CO LTD

Enterprise informatization management integration platform based on big data

PendingCN121979873AAvoid inconsistent calibersReduce the risk of difficult reviewDatabase updatingFinanceInformatizationSystems engineering
The invention belongs to the technical field of enterprise informatization management and big data integration, and particularly relates to an enterprise informatization management integration platform based on big data. Comprising an auditing element unified structured acquisition module, a main body unique identifier analysis and failure closed loop module, a caliber version and field mapping version joint locking module and an evidence index binding and consistency verification packaging module. The platform reads interface and field mapping from a service system log according to a configuration table, normalizes the interface and field mapping and writes the interface and field mapping into an event account book collocation state; executing main body gating on the original entry record to generate a main body identifier and writing back the main body identifier; when failure occurs, the reason code is written and blocked, and the failure evidence index is returned; performing node analysis on the aperture script and generating an aperture chain fingerprint; and serializing the event segments, calculating abstracts, constructing batch abstract roots, positioning first inconsistent serial numbers when recalculation is inconsistent, and scheduling and supplementary collection, so as to output a recheckable audit evidence packet. According to the invention, aperture consistency and evidence traceability can be realized.
Owner:HUAIAN DONGCHUANGXINGKE TECHNOLOGY CO LTD

Dynamic routing method and device based on Nginx and Lua, equipment and storage medium

The invention discloses a dynamic routing method and device based on Nginx and Lua, equipment and a storage medium, and belongs to the technical field of network communication, and the method comprises the steps: receiving a user request, obtaining a tenant number and an expression, constructing a recognition model, inputting the expression into the recognition model, outputting a classification label and a first confidence value, and introducing the first confidence value for judgment, and selecting an optimal path from the candidate path set given by the permission mapping table according to the path score, performing permission judgment on the optimal path, when the access permission of the optimal path exists, sending a user request to a back-end module corresponding to the optimal path, constructing a state record item, and pushing the record item to a system log. According to the method, a dynamic path scheduling mode taking expression semantics and tenant context as cores is constructed, so that closed-loop capabilities of identity recognition, content understanding, path control and behavior tracing are formed, and the method has relatively high deployment universality and service adaptability.
Owner:GUANGZHOU SIYUN DATA TECH CO LTD

Automatic testing method, system and equipment based on protocol configuration table and medium

The invention discloses an automatic testing method, system and equipment based on a protocol configuration table and a medium. The method specifically comprises the following steps: capturing a communication data packet between a game client and a game server; analyzing the communication data packet by using a protocol format reasoning algorithm based on a hidden Markov model to generate a protocol configuration table; constructing an automatic test robot, and simulating player behaviors based on the protocol configuration table to execute a protocol-level test; based on the protocol configuration table and the execution state of the test robot, preferentially exploring a high-risk branch path, and dynamically adjusting the test sequence; and constructing a defect root cause analysis engine according to a protocol level test result and a multi-modal detection result, and automatically positioning and outputting a problem root in combination with protocol data, game state data and a system log. According to the method, the whole process of game automatic testing is realized, the game problem is accurately and efficiently detected, the source is positioned, the manual testing cost and error are reduced, and the game testing quality and efficiency are improved.
Owner:广州三七极耀网络科技有限公司

Method and system for evaluating anti-fraud index

The invention discloses a method and a system for evaluating an anti-fraud index. The method comprises the following steps of: 1, acquiring and processing multi-source heterogeneous data; the multi-source heterogeneous data comprises telecommunication data, a social platform, historical fraud data, a user portrait and a system log; the data processing comprises text cleaning, voice-to-text conversion, image feature extraction and data anonymization; 2, calculating personal risk features, regional risk features and system efficiency features; 3, comprehensively evaluating an anti-fraud index based on the personal risk characteristics, the regional risk characteristics and the system efficiency characteristics; the method is based on a multi-dimensional index system of a personal risk index (PRI), a regional threat index (RTI) and a system efficiency index (SEI), and provides comprehensive support of accurate prevention and control, dynamic response and scientific decision for an anti-fraud system.
Owner:SICHUAN FENLING INFORMATION TECHNOLOGY CO LTD

Computer network security monitoring device and monitoring method

The invention discloses a computer network security monitoring device and monitoring method, and relates to the technical field of computer network security. An edge calculation module; a data analysis module; an alarm module; a response module; a storage module; wherein the data acquisition module comprises a network probe, a system log collector and user behavior monitoring software; the edge calculation module comprises a data cleaning unit, a data compression unit, an anomaly detection unit and an encryption transmission unit; and the data analysis module comprises a GBDT model unit, an One-Class SVM model unit, a rule engine unit and a model fusion unit, and solves the problems of low detection efficiency, high false alarm rate and slow response caused by the fact that the current network security monitoring technology depends on a single data source or model and the centralized processing is difficult to deal with mass data.
Owner:STATE GRID SICHUAN ELECTRIC POWER CO +2

Log processing method and system and storage medium

The invention provides a log processing method and system and a storage medium, and the method comprises the steps: receiving a communication message from client equipment; the communication message is routed to the cloud platform through the edge message cluster, and the communication message is forwarded to the target MQTT cluster through the cloud platform, so that the target MQTT cluster and the terminal equipment process the communication message, a system log generated by the target MQTT cluster is stored, and an error log is extracted from the system log; and analyzing the error log through an AI analysis module to generate error data. According to the method, the access pressure is dispersed through the edge message cluster, the cloud platform dynamically allocates the communication messages to the multiple target MQTT clusters according to the real-time state, and the single-node bearing bottleneck is broken through. And after the target cluster generates a system log, rapid fault positioning is realized through an error log extraction and AI analysis module, and stable communication under multi-device connection is ensured.
Owner:SICHUAN HONGMEI INTELLIGENT TECH CO LTD

Router system service abnormity self-healing method based on cloud AI

The invention belongs to the technical field of communication, and particularly relates to a router system service exception self-healing method based on cloud AI, which comprises the following steps: deploying an exception detection module at a router end, collecting system logs and state data in real time and generating a standardized exception report; uploading the report to a cloud AI server through an encrypted MQTT protocol; the cloud calls a hybrid analysis model composed of a rule matching engine, a machine learning classifier and a reinforcement learning decision network to generate a self-healing strategy instruction packet; the router end receives and executes the strategy, completes service restart, configuration rollback or hotfix loading and other operations, and verifies the self-healing effect; when communication interruption exceeds a threshold value, an embedded loopback self-healing subsystem is automatically activated, and abnormity is independently handled based on a local strategy library. According to the technical scheme, millisecond-level abnormal response and high-success-rate autonomous recovery can be achieved, the network availability and the service continuity are remarkably improved, and the disaster recovery self-healing capacity is still achieved when the cloud end is disconnected.
Owner:CHENGDU VOLANS TECH CO LTD

Method for detecting log abnormity of power dispatching automation system

The invention relates to the technical field of electric digital data processing, and discloses a method for detecting log abnormity of an electric power dispatching automation system, which comprises the following steps of: constructing a fixed depth analysis tree through historical log data, and extracting a log template based on word segmentation similarity; converting knowledge in the power dispatching field into vectors and storing the vectors into a knowledge base; retrieving knowledge base associated domain knowledge of the log template, inputting the large model to carry out abnormity judgment and marking a template label; after real-time log preprocessing, a template label is inherited through a parse tree matching template library and a self-adaptive threshold strategy, and online template updating is triggered for unmatched logs; and the context and high-frequency parameters of the abnormal log are aggregated, a dynamic cue word is constructed in combination with a retrieval result and a template feature weight, a large model is input for multi-dimensional root cause analysis, and template mechanism optimization is driven based on the cue word. The problems that in the prior art, manual maintenance is difficult, the generalization ability is weak, and the detection speed is low are solved, and the purposes of efficient detection, high accuracy and self-adaption are achieved.
Owner:STATE GRID ZHEJIANG ELECTRIC POWER CO LTD QUZHOU POWER SUPPLY CO

Automated threat hunting

Embodiments perform automated threat hunting in computing environments. A threat hunt plan is obtained to guide collection of candidate evidence items from evidence sources. Portions of candidate evidence items are discarded based on relevance scores, and evidence items are determined from non-discarded portions. Threat indicators associated with the evidence items are identified based on criteria in the threat hunt plan. Threat profiles are obtained based on the evidence items and threat indicators such that threat profiles include threat assessment metrics and are included in a report. Collection agents may interface with system logs, network traffic captures, endpoints, databases, email services, or user activity records to gather evidence items based on time ranges, filtering criteria, or sampling rates.
Owner:DROPZONE AI INC

Remote log pulling method and device, computer equipment and storage medium

The invention relates to a remote log pulling method and device, computer equipment and a storage medium. The method comprises the following steps: acquiring a log pulling task issued by a server; analyzing the log pulling task, and determining a to-be-extracted log type; determining a chip identifier and a system identifier corresponding to the log type; selecting a corresponding log extraction strategy according to the chip identifier and the system identifier, and extracting log data corresponding to the log type based on the log extraction strategy; the log extraction strategy comprises a cross-chip log extraction strategy or a cross-system log extraction strategy; and for the log pulling task, uploading log data to the server. By the adoption of the method, cross-chip and cross-system log extraction of the vehicle-mounted terminal can be achieved, the corresponding log data can be remotely uploaded according to the remotely issued log pulling task, workers do not need to go to the site, the labor cost is saved, and the log data processing efficiency of the vehicle-mounted terminal is improved.
Owner:WUHAN LOTUS CARS CO LTD