Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

608 results about "System call" patented technology

In computing, a system call is the programmatic way in which a computer program requests a service from the kernel of the operating system it is executed on. This may include hardware-related services (for example, accessing a hard disk drive), creation and execution of new processes, and communication with integral kernel services such as process scheduling. System calls provide an essential interface between a process and the operating system.

APT attack detection method based on large language model

The invention provides an APT (Advanced Persistent Threat) attack detection method based on a large language model, which comprises the following steps of: S1, extracting original system call event data from a kernel audit log of an operating system, and preprocessing the data; s2, constructing a multi-model collaborative detection architecture based on a large language model, and realizing fine-grained classification of network entities according to the preprocessed data through prompt construction, model fine tuning and a confidence scoring mechanism; s3, constructing an adaptive graph search algorithm based on multi-modal feature correlation modeling, driving attack path topology reconstruction, and realizing maximum reduction of a malicious sub-graph topology structure; s4, carrying out combination with MITRE ATTamp; the CK tactical knowledge base constructs a cyclic enhancement analysis framework, a cyclic enhancement technology is adopted to drive a large language model to execute hierarchical association reasoning, a mapping relation from malicious subgraphs to attack tactics and tactical chains is derived step by step, and finally an attack report summary and a targeted defense strategy are generated. According to the invention, APT attack detection with high accuracy and high interpretability is realized.
Owner:FUJIAN NORMAL UNIV

Intelligent quotation collaborative decision-making platform for enterprise products

The invention provides an enterprise product intelligent quotation collaborative decision-making platform. A platform architecture comprises a user interaction layer, a data processing layer and a decision-making layer, and platform functions are realized by relying on an intelligent agent. When a user releases a product quotation task, an authority management agent verifies the identity and access authority of the user, and a user interaction and demand analysis agent in a user interaction layer converts the natural language demand of the user into a structured instruction; the data processing layer receives an instruction, basic data and a special cost agent in the layer pull data from an external system through a cross-system calling agent, and a price calculation agent integrates the data through multi-objective optimization to generate candidate quoted prices; and finally, a man-machine cooperation and intelligent decision-making auxiliary agent in a decision-making layer displays all candidate schemes, and an expert performs fine adjustment to select an optimal quotation. According to the invention, rapid and accurate quotation is realized for enterprise products, the quotation model is continuously optimized through continuous feedback and self-learning, and finally a highly autonomous intelligent quotation system is formed.
Owner:BAOTOU KAIYUAN DIGITAL CO LTD

Automatic protocol adaptation method for real-time access system of multi-source equipment

The invention relates to an automatic protocol adaptation method for a real-time access system of multi-source equipment. The data acquisition layer receives original protocol data sent by equipment and transmits the original protocol data to the protocol adaptation layer. And the protocol metadata analysis module extracts, analyzes, compares and matches the data, and automatically identifies the protocol type of the equipment. The rule engine converts original protocol data into a system unified internal data format according to a conversion rule and then transmits the original protocol data to the data processing layer, and after cleaning, integration, analysis and other operations are carried out, the original protocol data are transmitted to the application interface layer to be called by an upper-layer application system. And when new protocol equipment is accessed, the hot plug function allows the system to dynamically load the new protocol adapter module in a state of not stopping running. According to the method, automatic adaptation of a new protocol is achieved through rapid deployment of the containerized micro-service architecture in combination with newly added protocol rules and metadata of the protocol management module, the whole process does not need to compile and publish the system again, and efficient and stable operation of the multi-source equipment real-time access system is guaranteed.
Owner:JIANGSU JARI GROUP CO LTD

VLA model method of humanoid robot for long-range task

PendingCN121234739ABiological modelsDesign optimisation/simulationEngineeringDynamic memory network
The invention relates to a long-range task-oriented VLA model method for a humanoid robot, which comprises the following steps of: S01, analyzing a natural language instruction through a space-time semantic analyzer to generate an atomic operation sequence with a space-time dependency relationship; s02, maintaining a task state machine by using a dynamic memory network, and tracking the task execution progress in real time; s03, integrating vision, language and sensor data through a multi-modal perception fusion engine; s04, calling a predefined action primitive based on an adaptive execution system and optimizing a motion track; and S05, performing online updating and optimization on the model through a continuous learning mechanism. According to the method, a natural language instruction is analyzed into a structured task sequence with space-time dependence through a space-time semantic analyzer, an execution sequence and preconditions are defined, the semantic understanding ability and the structuring degree of task planning are improved, and task decomposition and replanning in a dynamic environment are supported; according to the method, the LSTM and the knowledge graph are combined, and the task state is maintained in real time.
Owner:HUIZHOU BEIJIABAO ROBOT CO LTD

Enhanced LLM-RAG multi-hop question and answer method based on logic tree reasoning

The invention relates to an enhanced LLM-RAG multi-hop question and answer method based on logic tree reasoning, and belongs to the technical field of new-generation information, and the method comprises the following steps: inputting a multi-hop question and answer question into a computer system; the computer system calls a pre-training large language model LLM, the multi-hop question-answer question is decomposed into a hierarchical logic tree in a recursive mode, and each node of the logic tree comprises a sub-question and a corresponding hypothesis answer; performing image retrieval from a structured knowledge source Wikidata and performing text retrieval from an unstructured knowledge source Wikipedia on the basis of each node sub-question and the hypothesis answer to obtain corresponding evidence; traversing the logic tree, verifying the consistency between the hypothetical answer of each node and the evidence through LLM, if the contradiction exists, reconstructing the corresponding sub-tree, and dynamically correcting the reasoning path; and integrating the verified logic tree node information, and outputting an accurate answer to the multi-hop question and answer question.
Owner:GUIZHOU UNIV +1

Mitigating ransomware activity of a host system using a kernel monitor

A kernel monitor can be used to mitigate ransomware activity of a host system. In some aspects, a computing system can use the kernel monitor to monitor a set of system calls generated by the host system within a time window to perform a functionality. The kernel monitor can include a respective kernel program monitoring each system call in the set of system calls. The set of system calls can be filtered by the kernel monitor to identify a subset of system calls associated with encrypting a filesystem of the host system. The computing system can determine that the subset of system calls is indicative of ransomware activity associated with the host system based on the subset of system calls exceeding a predefined threshold. Subsequently, the computing system can perform a mitigation operation to mitigate the ransomware activity.
Owner:RED HAT INC

Synchronous main shift gear automatic compensation voltage control system

The invention relates to the technical field of voltage control, in particular to a synchronous main shift gear automatic compensation voltage control system, which comprises an area load information acquisition module, a voltage instantaneous value and a current instantaneous value are periodically read through a voltage transformer and a current transformer which are deployed on a key feeder line or a user side in a specified area, and the voltage instantaneous value and the current instantaneous value are acquired; and calculating to obtain an active power value and a reactive power value, adding a synchronous timestamp and a node position code to each collected value, transmitting and collecting the coded voltage value, active power value, reactive power value and timestamp information, organizing and storing according to a regional and time sequence, and establishing a regional load real-time measurement data set. According to the method, real-time capturing and structured processing of the system call number, the parameter and the return value are carried out on the L4T kernel event triggered by the target process PID, a serialized system call track is obtained, and an execution process recording path mainly driven by process behaviors is formed.
Owner:NANJING GORI AUTOMATION ENG CO LTD

Neuro-Generative Adversarial System for real-time detection and combating of malware morphing in high-density edge networks

ActiveDE202025106911U1Platform integrity maintainanceData packEmbedded security
A system for real-time detection and mitigation of morphing malware in high-density edge networks, consisting of: a data acquisition unit configured to receive, normalize, and encode multimodal telemetry data streams originating from at least one of the following domains: network traffic, process behavior, system call sequences, binary instruction traces, and control flow graphs; the data acquisition unit is further configured to compute feature embeddings over sliding time windows and apply privacy-preserving redactions prior to storage; a generative neural processor that is operationally coupled to the data acquisition unit and configured to generate synthetic morphing malware variants by learning probabilistic transformations of previously observed malicious data representations, maintaining semantic functionality while varying structural and behavioral features; a discriminative neural processor trained adversarially with the generative neural processor, wherein the discriminative neural processor is configured to detect morphing malware by evaluating a probability distribution over multimodal telemetry embeddings and classifying anomalous process and flow behaviors in real time; a coordination processor that is communicatively connected to both the generative neural processor and the discriminative neural processor and is configured to orchestrate adversarial co-training, regulate detection thresholds, calculate reinforcement-based penalties for false negative results, and trigger countermeasures as soon as a detection confidence level exceeds a predefined adaptive threshold; a secure, system-integrated inference and enforcement unit configured to perform low-latency countermeasures at the network edge, including selective packet filtering, flow isolation, process interruption, or system microsegmentation, based on instructions from the coordinating processor; and a hardware-embedded security enclave that is embedded in the system and configured to store cryptographic keys, neural model parameters, and integrity affirmation data to ensure the confidentiality, authenticity, and immutability of model artifacts and policy configurations.
Owner:ANAJAVADIDHODDI RAMACHANDRA NAIK CHAYAPATHI BENGALURU +7

Communication method for user program and virtual machine on microkernel Hypervisor

The invention discloses a method for communication between a user program and a virtual machine on a microkernel Hypervisor, the microkernel Hypervisor is provided with two shared memory areas, the shared memory area 1 is accessed by the user program and a root service Rootserver, the shared memory area 2 is accessed by the Rootserver and the virtual machine, the user program writes communication request data with the virtual machine into the shared memory area 1, and the user program writes communication request data with the virtual machine into the shared memory area 2. The method comprises the following steps that a VMM sub-thread is used as a shared memory area 1, a Rootserver is notified through inter-process communication, the Rootserver reads communication request data from the shared memory area 1, the communication request data is written into a shared memory area 2 after being analyzed by the VMM sub-thread, a system calls a syscale to transmit a communication request to a kernel, the kernel injects virtual interrupt into a virtual machine, and the virtual machine sends the communication request to the Rootserver. And an interrupt processing program of the virtual machine processes the communication request and writes a processing result into the shared memory area 2, then the processing result is returned to the Hypervisor through the Hypercall, and a Rootserver of the Hypervisor feeds back the processing result to a user program through the IPC. The method is designed for the microkernel Hypervisor environment, and the overall performance and efficiency of the embedded virtualization system are improved.
Owner:UNIV OF ELECTRONICS SCI & TECH OF CHINA

Mandatory access control method and device based on process function context

The invention discloses a mandatory access control method and device based on a process function context, and the method comprises the steps: collecting a security context associated with a system call initiated by a target process, so as to generate a standardized object description; mapping the object description into a target function classification identifier, so as to obtain a process function context view of the target process according to the target function classification identifier; constructing a target decision key for access decision based on the current policy era, the qualifier, the function classification identifier, the view identifier of the process function context view and the isolation domain abstract; and querying the multi-level cache according to the target decision key to determine a matched target access decision. Therefore, context-sensitive judgment and cross-component consistency taking the functional context as the center are realized.
Owner:BEIJING METRO INFORMATION DEV CO LTD

APT abnormal behavior detection method based on multi-dimensional feature fusion

The invention belongs to the technical field of network security, and discloses a multi-dimensional feature fusion-based APT abnormal behavior detection method, which comprises the following steps of: constructing a traceability graph by using an acquired system operation log, separating system call sequence information from acquired data, and respectively calculating point embedding of the traceability graph and sequence embedding of function call; and the two features are embedded and fused, and abnormal behavior discovery is carried out through a detection model based on the fused features, so that the generalization ability of the abnormal detection model is remarkably improved.
Owner:ZHEJIANG UNIV OF TECH

CPU affinity guarantee method, computer equipment, medium and product

The invention discloses a CPU affinity guarantee method, computer equipment, a medium and a product, and relates to the technical field of operating systems. The method comprises the following steps: acquiring CPU affinity mask parameters; creating an application starter process, and setting the CPU affinity of the application starter process as a CPU affinity mask parameter; based on a preset application program path, creating an application program process through an application starter process, and injecting the dynamic link library into a process space of the application program process; performing Hook operation on a preset CPU affinity related system API (Application Program Interface); system calling initiated by the application program process is monitored in real time according to the dynamic link library, and when it is detected that the application program process calls a target system API function in a preset CPU affinity related system API, a calling request of the target system API function is redirected to a preset processing function; therefore, the application program process is ensured to always run in the CPU core range limited by the CPU affinity mask parameters.
Owner:BEIJING JINGXING RUICHUANG SOFTWARE CO LTD

Operating system containerized kernel compatible method based on shadow structure mapping

The invention discloses an operating system containerization kernel compatibility method based on shadow structure mapping, which comprises the following steps of: constructing a multi-dimensional mapping rule base by analyzing the difference of data structures between a container system and a standard system, and creating a shadow structure comprising a data area, a metadata area and an expansion area when the container system runs on a host system; the host system allocates a shadow memory space and a memory pool, establishes mapping between a shadow structure and a physical memory page and bidirectional mapping between the shadow structure and a host structure, intercepts system call of a container application, obtains a target structure and allocates a shadow structure and a host structure memory, and sends the shadow structure and the host structure memory to the host system; according to the method, conversion from the target structure to the host structure is completed according to the multi-dimensional mapping rule base, the host machine completes calling through the host structure, then the calling result is reversely converted into the target structure and returned to the container application, and seamless compatibility of the container system and the host system is achieved under the condition that a user mode program of the container system is not modified.
Owner:北京麟卓信息科技有限公司

Fine-grained data mover

Disclosed in some examples are improvements to memory controllers on distributed memory systems that include a fine-grained data mover component that offloads management of memory commands accessing multiple smaller values to the memory controller. The fine-grained data mover (FGDM) may provide low host processing overhead that enables performance improvements for small task offloads. Work requests (“data mover calls”) may be sent by hosts to the FGDM without OS system calls. The FGDM is a virtually addressed data movement engine architected to transfer data at high transfer rates even during situations where the host has many small data movement requests and where the source and / or destination addresses are not memory controller friendly.
Owner:MICRON TECHNOLOGY INC

Graphic processor simulation method, simulator, device, equipment and storage medium

The invention discloses a graphics processor simulation method, a simulator, a device, electronic equipment and a storage medium, and belongs to the technical field of simulation. Loading a target system call simulator for simulating the target graphics processor; the target system call simulator comprises a user space simulation layer, a graphics processor simulation layer and a graphics drive simulation layer connected with the graphics processor simulation layer and the user space simulation layer; and running a target program in the user space simulation layer, and directly sending a graphic system call generated in the running process of the target program to the graphic drive simulation layer, so that the graphic drive simulation layer transmits a corresponding GPU instruction set to the graphic processor simulation layer based on the graphic system call, and executes the GPU instruction set through the graphic drive simulation layer. Therefore, the software and hardware of the corresponding graphics processor can be simulated by calling the simulator through the lightweight target system, and the simulation precision of the graphics processor can be improved under the condition of ensuring relatively high simulation efficiency.
Owner:LOONGSON TECH CORP

Large language model (LLM)-based agent operating systems

This disclosure describes a large language model (LLM)-based agent operating system comprising an application layer, a kernel layer, and a hardware layer. The kernel layer comprises an AIOS kernel comprising: LLM core(s), an agent scheduler, a context manager, a memory manager, a storage manager, and a system call interface configured to manage interactions among the agent scheduler, the context manager, the memory manager, and the storage manager.
Owner:RUTGERS THE STATE UNIV

Lightweight confidential container construction method based on hardware trusted environment

The invention provides a lightweight confidential container construction method based on a hardware trusted environment, which belongs to the technical field of confidential containers, and comprises a shared security memory module, a shared security storage module and a system call distribution module, according to the method, a lightweight confidential container is realized by utilizing an existing open source trusted execution environment operating system (OP-TEE) on end side embedded equipment supporting an ARM TrustZone technology; through the design based on the unique identifier of the confidential container, a plurality of confidential containers are realized in the TEE, and a plurality of trusted applications in the same confidential container have fine-grained secure memory and secure storage condition sharing, so that the communication overhead among the trusted applications in the confidential containers is reduced; the secure memory and the secure storage of the confidential container are strongly isolated from the untrusted world; according to the method, the development and deployment difficulty of the security sensitive application is reduced, and the resource utilization efficiency and the system expandability are remarkably improved while the confidentiality and integrity of hardware-level data are guaranteed.
Owner:NANKAI UNIV

Dynamic authority authorization and risk monitoring method and device, equipment and storage medium

The invention relates to the technical field of authority management, in particular to an authority dynamic authorization and risk monitoring method and device, equipment and a computer storage medium. According to the method, whether the request permission is necessary or not can be intelligently judged, and automatic response is performed in a low-risk situation, so that authorized popup windows during operation are remarkably reduced, and the user experience is improved; a dynamic granularity adjustment mechanism is introduced, one-time granting of full authority is avoided, and the privacy exposure risk is reduced while normal functions are guaranteed; the method has the capability of behavior detection during operation, can identify permission abuse behaviors and give an alarm in real time based on permission use frequency, calling context and behavior sequences, and fills up the defect of hysteresis of post-event analysis in an existing scheme; the method does not depend on any machine learning framework, completely adopts system calling, state machine judgment and configuration driving, is low in resource consumption and high in adaptability, can stably run on middle-end and low-end equipment, and has the industrialization landing capability.
Owner:SHANGHAI INNOVATECH INFORMATION TECH

Natural language driven situation awareness control method and system based on task intention and medium

The invention discloses a natural language driven situation awareness control method and system based on task intention and a medium. Relates to the technical field of artificial intelligence and man-machine interaction. Generating a natural language template library and a task intention field table based on the three-table knowledge; constructing an interface-data double-mapping knowledge graph by taking three-table knowledge as a construction basis and taking a natural language template library and a task intention field table as retrieval rearrangement tools, and then performing semantic retrieval and anaphora resolution to generate structured intention data; on the premise of not depending on a fixed layout, a user instruction is analyzed into a task intention, stable anchoring of an interface object is achieved through semantic positioning, and the task intention is automatically compiled into a system API call or interface event sequence; and meanwhile, the availability and compliance of execution are guaranteed through a closed-loop mechanism of credible execution scoring and minimization clarification, so that the operation complexity is effectively reduced, and the response efficiency and intelligent interaction level of the situation awareness system are improved.
Owner:TIANFU JIANGXI LAB

Cloud native security configuration system and method based on container analysis and LLM

The invention discloses a cloud native security configuration system and method based on container analysis and LLM, and the system comprises a mirror image static analysis module which is used for compiling a Linux kernel and a standard library source code to extract intermediate representation, and tracking and constructing a double-layer mapping relation library from the system call to the container capability; the dynamic binary extraction module is used for executing the container mirror image and extracting a binary file of a core function; the mirror image static and dynamic association module is used for executing two-stage static binary file analysis and extracting function requirements required by system calling and mirror image for loading during container running; and the cue word construction and model fine adjustment module is used for constructing cue words, performing fine adjustment on the LLM model and generating a minimum privilege function limitation configuration file of the container. According to the method, static analysis and runtime analysis are combined, the container mirror image is thoroughly checked, the function, which is specified by a user and exceeds the original definition of the mirror image, of the LLM model is finely adjusted through the cue word, and privileged function security configuration is generated according to specific requirements.
Owner:ZHEJIANG UNIV

Non-intrusive application runtime protection method and system based on eBPF

The invention discloses an eBPF-based non-intrusive application runtime protection method and system, and the method comprises the steps: firstly collecting BTF information of a target operating system, generating an eBPF kernel program adaptive to a local kernel version according to the BTF information, and loading the eBPF kernel program to an LSM control point of an operating system kernel; generating legal behavior description configuration according to known operation information of the protected application, and distributing the legal behavior description configuration to a corresponding storage mechanism of an eBPF Map in a kernel; when a protected application initiates a system call, an eBPF kernel program mounted on a corresponding LSM control point intercepts and queries legal behavior description configuration in an eBPF Map, if the system call is matched with the legal behavior description configuration, execution is allowed, and if the system call is not matched with the legal behavior description configuration, the call is blocked, so that the application is effectively protected during running, and the method has the non-invasive characteristic. Application codes are prevented from being modified; the kernel is adapted based on BTF information, so that the program stability and compatibility are guaranteed; illegal calling is effectively prevented through a legal behavior description mechanism, and a reliable environment is provided for application running.
Owner:NORTHWESTERN POLYTECHNICAL UNIV

Data transmission method and device, equipment, storage medium and computer program product

The invention discloses a data transmission method and device, equipment, a storage medium and a computer program product, and the method comprises the steps that first equipment responds to first system call of an application process, and divides a first data buffer area into a plurality of sections; the first data buffer area is used for buffering first data written by an application process; allocating a first mbuf and a plurality of second mbufs from the first memory pool based on the plurality of sections; the first mbuf is used for storing message header information corresponding to a first message, and the first message represents a message used for transmitting first data; each second mbuf in the plurality of second mbufs is used for indicating one section; linking one first mbuf and a plurality of second mbufs into a first linked list, and mapping the first linked list into a network card, so that the network card sends a first message to the second equipment; the first linked list is used for the network card to read the first data from the first data buffer area and encapsulate the first data into a first message.
Owner:CHINA MOBILE (SUZHOU) SOFTWARE TECH CO LTD +1

Method and device for creating executable program code segment read-only file mapping memory copy

The invention relates to the technical field of program loading and memory management, and provides a method and equipment for creating an executable program code segment read-only file mapping memory copy, and the method comprises the steps: in a system of an NUMA architecture, when a process is executed on a certain NUMA node, mapping a code segment in a read-write mode; traversing all pages mapped by the code segment, reading one byte from each page and writing back the byte, triggering a missing page processing flow, and completing the distribution of the code segment memory copy of the process; and carrying out locking and authority control on the code segment memory copy through system calling. According to the method and equipment for creating the executable program code segment read-only file mapping memory copy, the execution performance of the program under the NUMA architecture is remarkably improved through an innovative process level code segment copy scheme and a flexible implementation mode.
Owner:CHINA ELECTRONICS CLOUD DIGITAL INTELLIGENCE TECH CO LTD

Isolated test environment for ransomware analysis

Techniques are provided for an isolated test environment for ransomware analysis. One or more enterprise applications are assigned to one or more server systems to be provisioned in an isolated test environment. An enterprise replica is generated in the isolated test environment by provisioning the one or more server systems and deploying the one or more enterprise applications on the one or more server systems. A kernel monitoring component is deployed on the one or more server systems in the isolated test environment. The kernel monitoring component is configured to generate kernel telemetry data for a plurality of system calls initiated by processes executing on the one or more server systems. A selected ransomware variant is deployed in the isolated test environment. An effect of the selected ransomware variant on the enterprise replica is determined based on analyzing the kernel telemetry data.
Owner:MIMIC NETWORKS INC

Heterogeneous program log-oriented semantic unification and anomaly traceability analysis method and system

The invention discloses a semantic unification and anomaly traceability analysis method and system for heterogeneous program logs, and the method comprises the steps: firstly collecting original logs in various formats, and packaging the original logs into standard objects in a unified manner; thirdly, identifying fields through a rule and a semantic model, uniformly mapping and labeling semantic tags, eliminating semantic differences, and constructing log data with uniform semantics; automatically constructing a cross-system call chain based on the request identifier and the like; secondly, extracting log features and comparing the log features with a normal behavior model to carry out anomaly detection, and generating an abnormal event; combining time, calling and dependency to construct an anomaly propagation path, and reversely backtracking and positioning an anomaly source; abnormal priority scores are calculated according to the propagation range, the influence degree and the like, and sorting and visual display are carried out; through unified semantic modeling and automatic association analysis of heterogeneous logs, accurate tracing and intelligent positioning of cross-service link anomalies are realized, the operation and maintenance efficiency is effectively improved, and the dependence on artificial experience is reduced.
Owner:NARI TECH CO LTD +1

Linux-based domestic operating system kernel cutting optimization system

The invention relates to the field of system optimization, and discloses a Linux-based domestic operating system kernel cutting optimization system, which comprises a hardware baseline identification module used for acquiring a processor architecture, peripheral and bus topology, storage and network resources and firmware capability of target equipment and generating hardware baseline description; the scene portrait construction module is used for statically and dynamically observing a target application and acquiring operation portrait data including system calling, driving access and interruption events to form a scene portrait; a dependency analysis module; a multi-target constraint solving module; configuring a synthesis and construction module; and a verification and difference feedback module. According to the method, portrait analysis is carried out on calling of a target application, driving access and interruption events, a trigger threshold value is set, dependency solving is executed in a high touch module range, scene-driven cutting decision is achieved, the dependency closure calculation range is made to be consistent with an actual operation behavior, redundancy and invalid dependency are reduced, and cutting precision and kernel construction efficiency are improved.
Owner:BEIJING ZHONGKE ANJIE TECH DEV

Large language model (LLM) risk mitigation

Disclosed are various approaches for large language model (LLM) application risk mitigation. A large language model (LLM) application that interacts with a network LLM service can be identified. A portion of the LLM application can be provided as input to an LLM risk mitigation code generation function that outputs LLM-specific risk mitigation code. A runtime environment can be deployed to include a modified version of the LLM application that includes the LLM-specific risk mitigation code, a kernel-layer LLM risk mitigation program that can intercept LLM interaction system calls to apply the LLM-specific risk mitigation code, or any combination thereof.
Owner:AMERICAN EXPRESS TRAVEL RELATED SERVICES CO INC

Node distribution method and system for GPU use process in NUMA environment

The invention discloses a node distribution method and system for a GPU (Graphics Processing Unit) use process in an NUMA (Non Uniform Memory Access) environment, and the method comprises the following steps: in a kernel mode, capturing an event that the process executes a new program and collecting meta-information of the process through an eBPF program mounted at a system call entry tracking point, and judging whether the process is a target GPU process or not based on the collected meta-information of the process; if the process is the target GPU process, transmitting meta-information of the process to a user mode, and if the process is not the target GPU process, ending and exiting; and for the meta-information transmitted to each target GPU process of the user mode, reading the meta-information of the target GPU process through the user mode daemon process, evaluating each node in the NUMA environment based on a preset node allocation rule, selecting an optimal NUMA node, and binding the target GPU process to a CPU of the optimal NUMA node for execution. The GPU computing efficiency and the resource utilization rate can be improved.
Owner:KYLIN CORP

Heap ejection attack defense method and system based on eBPF and memory detection

The invention discloses a heap ejection attack defense method and system based on eBPF and memory detection, and belongs to the technical field of system security. The method comprises the following steps: detecting space memory allocation of an operating system compiled with an eBPF program; establishing an abnormal distribution detection model based on the normal behavior; judging whether the memory allocation request is normal or not by using an abnormal allocation detection model; continuously monitoring a subsequent system calling condition of the abnormal memory allocation request, and judging whether a calling chain required by a malicious behavior is executed or not; and establishing service safeguard measures to ensure normal and stable operation of the operating system. According to the method, the non-invasive eBPF program is added on the operating system, and the dynamic programming characteristic of the eBPF kernel is utilized, so that the modification of kernel codes and user program codes is avoided, and the implementation is more flexible; the method is effective for operating system kernels of different versions, non-intrusive defense addition is achieved for firmware, the kernel does not need to be recompiled, and the system calling parameter monitoring and data obtaining capacity is provided.
Owner:NANJING UNIV OF POSTS & TELECOMM

Fuzzy test input generation method based on characteristic unification and related equipment

The invention relates to the technical field of kernel fuzz testing, and provides a fuzz test input generation method based on characteristic unification and related equipment, the method comprises the following steps: generating a function call graph and a plurality of control flow graphs of a target system, and integrating the function call graph and all the control flow graphs to obtain an inter-program control flow graph; constructing a kernel code calling chain based on the inter-program control flow diagram; carrying out characteristic unified representation modeling based on the kernel configuration file and the kernel code call chain of the target system, and generating a configuration code relation mapping table; extracting related information of the characteristic related interface function according to the kernel code call chain, and performing grammar conversion based on the related information to generate a system call test protocol template of the characteristic related interface function; and generating fuzzy test input of the target system based on the system call test protocol template and the configuration code relation mapping table. According to the method provided by the invention, the correlation between kernel characteristic configuration and fuzzy test input can be improved.
Owner:CENT SOUTH UNIV