Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

24 results about "Targeted threat" patented technology

Targeted threats are a class of malware destined for one specific organization or industry. A type of crimeware, these threats are of particular concern because they are designed to capture sensitive information. Targeted attacks may include threats delivered via SMTP e-mail, port attacks, zero day attack vulnerability exploits or phishing messages. Government organisations are the most targeted sector. Financial industries are the second most targeted sector, most likely because cybercriminals desire to profit from the confidential, sensitive information the financial industry IT infrastructure houses. Similarly, online brokerage accounts have also been targeted by such attacks.

Computing power resource management method, device and equipment

The invention provides a computing power resource management method, device and equipment, and relates to the technical field of networks. The method comprises the following steps: acquiring a first threat type corresponding to first multi-source data of a computing power network; based on the target risk assessment model, processing the first threat type to obtain target information corresponding to the computing power network, the target information comprising a target isolation measure and a target threat priority; determining a target management strategy according to the target isolation measure and the target threat priority; and executing a target management strategy, wherein the target management strategy is used for managing computing power resources in the computing power network. According to the embodiment of the invention, the method can dynamically determine the management strategy of the computing power resources in the computing power network, thereby guaranteeing the efficient utilization of the computing power resources, and improving the safety and stability of the computing power network.
Owner:CHINA UNITED NETWORK COMM GRP CO LTD

Network security protection method based on distributed threat identification and related equipment

The invention discloses a network security protection method and device based on distributed threat identification, and relates to the field of network security. The method comprises the following steps: firstly, determining target acquisition granularity and frequency based on equipment type distribution, service load and link quality data; capturing the original flow in real time by an edge computing node, and extracting a distributed threat fingerprint containing a behavior sequence and a protocol variation feature; after block chain consensus verification, synchronizing to a collaborative detection network, and constructing an on-chain trusted threat knowledge base; simulating a target threat fingerprint propagation path in combination with real-time network topology and an on-chain trusted threat knowledge base, and generating a dynamic threat propagation map; and determining a multi-dimensional risk score based on the atlas, and further generating a self-adaptive protection strategy and issuing and executing the self-adaptive protection strategy. According to the method, technologies such as multi-dimensional data perception, edge calculation and block chain consensus are fused, and efficient, credible and real-time response distributed network security protection is realized.
Owner:SHANDONG XIEHE UNIV +1

Threat intelligence based trustworthiness updating method and device and electronic device

The application discloses a credibility updating method and device based on threat intelligence and electronic equipment, and the credibility updating method comprises the following steps: obtaining the intelligence type and intelligence information of target threat intelligence; determining the intelligence weight value of the credibility of the target threat intelligence in each preset dimension based on the intelligence information; determining the initial credibility score of the target threat intelligence based on the intelligence type and all the intelligence weight values; updating the target credibility score of the target threat intelligence based on the initial credibility score; and performing aging processing on the target threat intelligence if the target credibility score is less than a preset credibility threshold. The application solves the technical problem that the change of the credibility of threat intelligence under the influence of multiple dimensions cannot be determined in the related art.
Owner:HILLSTONE NETWORKS CO LTD

Threat situation analysis method and device, electronic equipment and storage medium

PendingCN120658457ASecuring communicationAttackTargeted threat
The invention discloses a threat situation analysis method and device, electronic equipment and a storage medium. The method comprises the following steps: acquiring alarm information to be analyzed; inputting the to-be-analyzed alarm information into a target security big model, performing attack event detection on the to-be-analyzed alarm information based on a preset attack event information set, and performing threat situation analysis on the to-be-analyzed alarm information based on a corresponding target attack event detection result and a threat intelligence library, and outputting a target threat situation analysis result corresponding to the to-be-detected alarm information, so that attack event detection can be automatically performed on the to-be-analyzed alarm information with high precision and low misjudgment rate, the problem of misjudgment or missing detection in manual detection is avoided, and the target security big model can be utilized to improve the security of the to-be-detected alarm information. In combination with the target attack event detection result corresponding to the alarm information to be analyzed and the threat intelligence in the threat intelligence library, more accurate and efficient threat situation analysis is realized, and the perceptual ability of the system to the threat situation is improved.
Owner:BEIJING HONGTENG INTELLIGENT TECH CO LTD

A safety monitoring method and device, electronic equipment and storage medium

Embodiments of the present application provide a kind of security monitoring method, device, electronic equipment and storage medium, the method comprises: based on the position of each object in target area, all objects in target area are divided into multiple object combinations;For any object combination, based on the category information of each object in object combination, the situation information of each object in object combination, the environmental parameter corresponding to target area and the target monitoring task corresponding to target area, determine the target threat value of threat degree of object combination;Based on the target threat value corresponding to all object combinations in target area, the security of target area is monitored.Based on position, the object in target area is divided into multiple object combinations, and individual object and aggregated object are distinguished;By comprehensively considering multiple factors, the target threat value that accurately reflects the threat degree of single object or multiple aggregated objects in specific task and specific environment is obtained, so as to accurately monitor the security.
Owner:CHINA ORDNANCE SCI INST

Router threat detection method and device and electronic equipment

The invention discloses a router threat detection method, a router threat detection device and electronic equipment, relates to the technical field of network security, and is used for improving the anomaly detection accuracy of routing equipment. The method comprises the following steps: firstly, calculating a target feature matrix based on N pieces of real-time network flow data; then, calculating a dynamic adjustment parameter based on the target feature matrix, and performing parameter adjustment on the initial threat detection model according to the dynamic adjustment parameter to obtain a target threat detection model; and finally, detecting whether the N pieces of real-time network flow data are abnormal or not by adopting the target threat detection model. According to the method, four types of unique flow characteristics are adopted, whether the current routing equipment is abnormal or not can be obviously reflected, and the accuracy of detecting the threat of the routing equipment is improved. Besides, the dynamic adjustment parameters of the model are dynamically adjusted, so that the model can better adapt to the change of the traffic characteristics of the routing equipment, and the accuracy and adaptability of the threat detection of the routing equipment are improved.
Owner:CHINA TELECOM CORP LTD TECHNOLOGY INNOVATION CENTER +1

Method for generating threat intelligence data and related device

PendingCN122339724AAttackEngineering
The threat intelligence data generation method and related equipment provided by the embodiments of the present application, the method comprises the following steps: firstly, acquiring multi-source heterogeneous alarm data and external multi-source intelligence data; then, performing feature analysis based on the multi-source heterogeneous alarm data to obtain an attack capability score of an attack end and a comprehensive risk score of a target side, and obtaining enhanced intelligence data based on the attack capability score and the comprehensive risk score; next, performing matching retrieval on the external multi-source intelligence data based on the enhanced intelligence data to obtain a matching degree, and obtaining an update credibility weight of each external intelligence source in the external multi-source intelligence data based on the matching degree; then, performing weighted fusion on the external multi-source intelligence data based on the update credibility weight to generate an external comprehensive threat score; finally, obtaining target threat intelligence data based on the enhanced intelligence data and the external comprehensive threat score, so that accurate data support can be provided for a defense system, and high-value security decisions can be effectively assisted.
Owner:PENG CHENG LAB

Rapid matching selection method for electric-thermal collaborative strategy

PendingCN121563138AOffice automationTargeted threatReliability engineering
The invention discloses an electric-fire cooperation strategy rapid matching selection method, which aims at an electric-fire cooperation problem, combines obtained combat data to generate a target threat degree level, and realizes autonomous electric-fire rapid matching cooperation based on strategies under different tasks and specific capabilities of a fire platform. The method can provide support for evaluation and analysis of combat.
Owner:NO 8511 RES INST OF CASIC

A threat intelligence fusion method and device, electronic equipment and storage medium

ActiveCN115643094BSecuring communicationData miningTargeted threat
The application provides a threat intelligence fusion method and device, electronic equipment and storage medium. The method comprises the following steps: acquiring a plurality of threat intelligence data to be fused, wherein the intelligence values of the threat intelligence data to be fused are all target intelligence values; determining the threat intelligence data to be fused as target threat intelligence data, wherein the intelligence source confidence value of the threat intelligence data to be fused is greater than a first threshold value; for each judgment type, performing data fusion processing on the judgment value corresponding to the current judgment type in each target threat intelligence data, so as to obtain a fused judgment value corresponding to each judgment type; and generating fused threat intelligence data according to the target intelligence value and each fused judgment value. In the application, if the same intelligence value has a plurality of corresponding threat intelligence data to be fused, the method provided by the application can screen out the fused threat intelligence data with higher accuracy and after fusion processing, so that when the threat intelligence data is used subsequently, how to use can be determined directly according to the fused threat intelligence data corresponding to the intelligence value.
Owner:HARBIN ANTIY TECH

Smart contract threat transaction sequence generation method and system

The application provides a smart contract threat transaction sequence generation method and system, which comprehensively identifies and simulates potential security vulnerabilities in smart contracts by using static analysis and dynamic behavior prediction technology. This method generates targeted threat transaction sequences, which not only predict and demonstrate possible attack paths and their actual exploitation of contract vulnerabilities, but also allow developers to make precise repairs and enhance contract security. Automated vulnerability detection and threat sequence generation significantly reduces the burden of manual audits, significantly improves audit efficiency, and can complete security evaluation of a large number of contracts in a short time, effectively supporting the security needs of large-scale blockchain projects. In addition, the system designs a threat transaction sequence construction function specifically for the complex interactivity of smart contracts, which can deeply analyze and solve deep-seated security challenges in contract interaction.
Owner:GUANGZHOU INSTITUTE OF TECHNOLOY XIDIAN UNIVERSITY +3

A multi-source threat intelligence fusion analysis method and system for network security

The present invention discloses a multi-source threat intelligence fusion analysis method and system for network security. The method includes: aligning target threat intelligence data in two target threat intelligence data sequences based on positional relationship, and calculating the second correlation between each group of aligned target threat intelligence data, and then determining the target correlation between two target threat intelligence data sequences based on the second correlation between each group of target threat intelligence data and the target weight corresponding to each group of target threat intelligence data, and judging whether the target correlation between the two target threat intelligence data sequences is greater than a preset threshold. If it is greater than the preset threshold, the two cluster centers corresponding to the two target threat intelligence data sequences are associated. The target threat intelligence data with potential correlation can be fused together, thereby improving the integration efficiency of threat intelligence in the fusion process.
Owner:JIANGXI COPPER

A target threat assessment model training method and evaluation method

The present invention discloses a target threat assessment model training method and evaluation method, which uses an LSTM network to extract the temporal characteristics of threat assessment indicators, and combines the rankNet network structure to directly learn the threat ranking between two targets, making full use of the relative threat information between targets, and effectively improving the accuracy of target threat ranking of multiple targets.
Owner:CHINA ORDNANCE EQUIP GRP AUTOMATION RES INST CO LTD

Intelligent networking automobile-oriented threat analysis method, device, medium and program product

Embodiments of the present application provide a threat analysis method, device, medium and program product for intelligent networking cars, relating to the technical field of automobile information security. The method comprises: determining a target attack path corresponding to a target business scenario and a target modeling component corresponding to the target attack path according to a rule library constructed for intelligent networking cars; wherein the rule library is constructed according to the corresponding relationship between each business scenario in a business scenario library and each attack path in an attack path library, and the corresponding relationship between each attack path and each modeling component in a modeling component library; the target business scenario is a business scenario specified by a user from the each business scenario; establishing a threat model by connecting the target modeling component according to the target attack path; and searching for target threat data matched with the threat model from a threat database. The embodiments of the present application can achieve the technical effect of automatically performing threat modeling analysis for intelligent networking cars.
Owner:BEIJING TOPSEC NETWORK SECURITY TECH +2

Threat intelligence determination method and apparatus, storage medium

The application discloses a threat intelligence determination method and device and a storage medium. Relates to the technical field of data processing, the field of network security and other related technical fields, and the method comprises the following steps: determining potential threat information in target data; determining the target category corresponding to the potential threat information according to a preset threat detection condition; in the case that the target category is a first threat category or a second threat category, determining the target threat intelligence corresponding to the target data according to the processing method corresponding to the target category. Through the application, the determination accuracy of threat intelligence can be improved.
Owner:HILLSTONE NETWORKS CO LTD

Ebpf and xdp based ipv6 fragmentation bypass threat detection method and system

The application relates to the technical field of network security, in particular to an IPv6 fragmentation bypass threat detection method and system based on eBPF and XDP, which sets a data packet observation point at a network driver layer, the data packet observation point is used for mounting an extended Berkeley packet filter (eBPF) program on a data packet processing path by using a fast data path (XDP) technology; for a data packet received on the network driver layer, the data packet observation point calls the eBPF program on an XDP network hook, the eBPF program is used for identifying and filtering a data packet with potential threats by using a feature matching strategy, the feature matching strategy is used for extracting key features of the data packet, matching the extracted key features of the data packet with target threat features, and judging whether an upper layer header of the data packet is complete; the application realizes efficient detection of specific threats by combining the dynamic programmability of the eBPF and the high-performance data packet processing capability of the XDP, meets the task requirements of an IPv6 network security threat high-performance solution, and has a smaller influence on system stability even under serious threats.
Owner:Chinese People's Liberation Army Cyberspace Force Information Engineering University

An abnormal traffic data generation method, device, equipment and medium

PendingCN122457348AData sourceData mining
The application discloses an abnormal traffic data generation method and device, equipment and medium, and relates to the field of network security, comprising: constructing a structured knowledge base; the structured knowledge base comprises a network topology knowledge base and a threat intelligence knowledge base, the network topology knowledge base is constructed based on information extracted from a preset network topology data source, and the threat intelligence knowledge base is constructed based on information extracted from a preset threat intelligence data source; a generative pre-training model is used as a base model, and the base model is fine-tuned based on the network topology knowledge base and the threat intelligence knowledge base in sequence to obtain a fine-tuned model; a target network topology description and a target threat intelligence description are input into the fine-tuned model to obtain abstract packet descriptions that meet topology constraints corresponding to the target network topology description and semantic requirements corresponding to the target threat intelligence description and output by the fine-tuned model; and the abstract packet descriptions are converted into executable physical network packets and output as abnormal traffic data.
Owner:PENG CHENG LAB

Security quality evaluation device, security quality evaluation system, security quality evaluation method, and security quality evaluation program

PCT designated stageWO2026042291A1Platform integrity maintainanceCountermeasureTargeted threat
A zone model generation unit (112) has a first axis for a countermeasure value serving as an index of the number of countermeasures to be applied to security threats, and a second axis for a threat value serving as an index of the number of threats to be dealt with, and generates one or more zone models in which a space formed by the first axis and the second axis is divided into a plurality of zones and a security opinion is set for each zone. A zone analysis unit (113) identifies a target countermeasure value and a target threat value on the basis of countermeasure threat information of one or more evaluation targets, and acquires an opinion corresponding to a set of the target countermeasure value and the target threat value from the zone model as a quality opinion for the quality of security of the evaluation target.
Owner:MITSUBISHI ELECTRIC CORP

Cross-domain target threat degree dynamic evaluation method based on combination of analytic hierarchy process and entropy weight method

The invention discloses a cross-domain target threat degree dynamic assessment method based on an analytic hierarchy process and an entropy weight method, and relates to the technical field of target threat degree dynamic assessment. According to the method, a hierarchical structure is constructed through the AHP-entropy weight method, a complex nonlinear problem is decomposed into multistage linear subtasks, the calculation complexity is remarkably reduced, and the real-time performance is improved; traditional static prior knowledge dependence is abandoned, weight coefficient self-correction is achieved based on the comparison relation between real-time data streams and elements, and it is ensured that the weight dynamically adapts to scene changes; subjective weighting and objective entropy weight are fused, single-dimensional deviation is eliminated through a multi-level calibration mechanism, a comprehensive evaluation system cooperatively driven by data and knowledge is constructed, and the result robustness is improved.
Owner:XIDIAN UNIV

An attack posture analysis method and related apparatus

ActiveCN118337515BSecuring communicationAttackTargeted threat
The application provides an attack situation analysis method and related device, which can be applied to the field of network security or finance, and the method comprises the following steps: acquiring alarm data of blocked IP and external threat intelligence of the blocked IP in a preset period; extracting a plurality of attack situation characteristics of the blocked IP from the alarm data and the external threat intelligence; dividing the plurality of attack situation characteristics into a plurality of index groups, and each index group corresponds to an attack characteristic dimension; determining a threat level corresponding to each index group according to the attack situation characteristics in each index group; generating a target threat level combination according to the threat level corresponding to each index group; and querying a pre-set threat level combination scoring table according to the target threat level combination to obtain a threat score of the blocked IP. The application can quickly, comprehensively and accurately analyze the attack situation periodically, which helps to adjust the network security protection level in time according to the attack situation and improve the network security.
Owner:BANK OF CHINA

A multi-state target threat assessment and collaborative management method for low-altitude economy

PendingCN122454790AData setCountermeasure
The application discloses a kind of multi-state target threat assessment and collaborative management methods for low-altitude economy, with situation base map as global data set, low-altitude target is divided into compliance, transition state and non-compliant three states and implements unified control, when the target broadcast effective RID has held VID, identity trusted merging is realized by double track tracking and merging consistency comparison;Threat assessment adopts the double-channel architecture of data-driven and expert rule parallel, with compliance deviation degree as common input;When generating evasion route for compliance and transition state target, the evasion route is written into flight plan database as temporary equivalent authorized route synchronously, so that threat assessment calculates deviation according to updated reference route, thereby avoiding evasion behavior being misjudged as route deviation. Before executing countermeasure, compliant targets and transition state targets in the influence domain are identified and disposed by linkage effect prediction, evasion instructions are issued to them first and then execution is disposed, to realize differentiated collaborative management.
Owner:JIANGSU POLICE INST

Network security assessment method and device, storage medium and program product

The invention discloses a network security assessment method and device, a storage medium and a program product, and the method comprises the steps: carrying out the network connection of a plurality of asset nodes based on an attack technology chain, and obtaining a plurality of attack paths; under one or more threat levels, performing protection evaluation on each attack and defense scene in one or more attack and defense scenes corresponding to each attack path based on the multi-source data to obtain a protection success rate of each attack and defense scene under each threat level; based on the protection success rate of one or more attack and defense scenes corresponding to each attack path under each threat level, performing quantitative evaluation on each attack path to obtain the path accessibility of each attack path under each threat level; performing comprehensive quantification processing on the path accessibility of each attack path under each threat level to obtain a target threat defense level; wherein the target threat defense level represents the highest threat level effectively defended in the network security protection system.
Owner:MIGU CO LTD +1

Security quality evaluation device, security quality evaluation system, security quality evaluation method, and security quality evaluation program

ActiveJP7745808B1Platform integrity maintainanceTargeted threatSystem safety
The zone model generation unit (112) has a first axis for a countermeasure value that is an index of the number of countermeasures applied to a security threat, and a second axis for a threat value that is an index of the number of threats to be countered, and divides a space formed by the first axis and the second axis into a plurality of sections, and generates one or more zone models in which a security opinion is set for each section.The zone analysis unit (113) identifies a target countermeasure value and a target threat value based on countermeasure threat information of one or more evaluation targets, and obtains an opinion corresponding to the pair of the target countermeasure value and the target threat value from the zone model as a quality opinion for the security quality of the evaluation target.
Owner:MITSUBISHI ELECTRIC CORP

Data processing method, device, equipment and medium

ActiveCN115499240BSecuring communicationSecurity MeasureTargeted threat
The embodiments of the present application provide a data processing method, apparatus, device, and medium to address the problems of the prior art in which, when a security incident occurs, the implementation efficiency of security measures is low due to over-reliance on manual judgment, and the accuracy of security measures is low due to the determination of security measures based on manual experience. In the embodiments of the present application, after determining that a target threat event is a preset event and the number of times the target threat event is received reaches a preset number, the electronic device determines the node corresponding to the target threat event in the event processing map and obtains the node related to the security measure connected to the node. This can avoid determining security measures based solely on manual experience when a security incident occurs, improve the accuracy of security measure determination, and avoid the problem of low efficiency of security measure implementation due to over-reliance on manual judgment.
Owner:NSFOCUS INFORMATION TECHNOLOGY CO LTD +1