Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

12 results about "Targeted threat" patented technology

Targeted threats are a class of malware destined for one specific organization or industry. A type of crimeware, these threats are of particular concern because they are designed to capture sensitive information. Targeted attacks may include threats delivered via SMTP e-mail, port attacks, zero day attack vulnerability exploits or phishing messages. Government organisations are the most targeted sector. Financial industries are the second most targeted sector, most likely because cybercriminals desire to profit from the confidential, sensitive information the financial industry IT infrastructure houses. Similarly, online brokerage accounts have also been targeted by such attacks.

Network security protection method based on distributed threat identification and related equipment

The invention discloses a network security protection method and device based on distributed threat identification, and relates to the field of network security. The method comprises the following steps: firstly, determining target acquisition granularity and frequency based on equipment type distribution, service load and link quality data; capturing the original flow in real time by an edge computing node, and extracting a distributed threat fingerprint containing a behavior sequence and a protocol variation feature; after block chain consensus verification, synchronizing to a collaborative detection network, and constructing an on-chain trusted threat knowledge base; simulating a target threat fingerprint propagation path in combination with real-time network topology and an on-chain trusted threat knowledge base, and generating a dynamic threat propagation map; and determining a multi-dimensional risk score based on the atlas, and further generating a self-adaptive protection strategy and issuing and executing the self-adaptive protection strategy. According to the method, technologies such as multi-dimensional data perception, edge calculation and block chain consensus are fused, and efficient, credible and real-time response distributed network security protection is realized.
Owner:SHANDONG XIEHE UNIV +1

Threat intelligence based trustworthiness updating method and device and electronic device

The application discloses a credibility updating method and device based on threat intelligence and electronic equipment, and the credibility updating method comprises the following steps: obtaining the intelligence type and intelligence information of target threat intelligence; determining the intelligence weight value of the credibility of the target threat intelligence in each preset dimension based on the intelligence information; determining the initial credibility score of the target threat intelligence based on the intelligence type and all the intelligence weight values; updating the target credibility score of the target threat intelligence based on the initial credibility score; and performing aging processing on the target threat intelligence if the target credibility score is less than a preset credibility threshold. The application solves the technical problem that the change of the credibility of threat intelligence under the influence of multiple dimensions cannot be determined in the related art.
Owner:HILLSTONE NETWORKS CO LTD

A safety monitoring method and device, electronic equipment and storage medium

Embodiments of the present application provide a kind of security monitoring method, device, electronic equipment and storage medium, the method comprises: based on the position of each object in target area, all objects in target area are divided into multiple object combinations;For any object combination, based on the category information of each object in object combination, the situation information of each object in object combination, the environmental parameter corresponding to target area and the target monitoring task corresponding to target area, determine the target threat value of threat degree of object combination;Based on the target threat value corresponding to all object combinations in target area, the security of target area is monitored.Based on position, the object in target area is divided into multiple object combinations, and individual object and aggregated object are distinguished;By comprehensively considering multiple factors, the target threat value that accurately reflects the threat degree of single object or multiple aggregated objects in specific task and specific environment is obtained, so as to accurately monitor the security.
Owner:CHINA ORDNANCE SCI INST

Method for generating threat intelligence data and related device

PendingCN122339724AAttackEngineering
The threat intelligence data generation method and related equipment provided by the embodiments of the present application, the method comprises the following steps: firstly, acquiring multi-source heterogeneous alarm data and external multi-source intelligence data; then, performing feature analysis based on the multi-source heterogeneous alarm data to obtain an attack capability score of an attack end and a comprehensive risk score of a target side, and obtaining enhanced intelligence data based on the attack capability score and the comprehensive risk score; next, performing matching retrieval on the external multi-source intelligence data based on the enhanced intelligence data to obtain a matching degree, and obtaining an update credibility weight of each external intelligence source in the external multi-source intelligence data based on the matching degree; then, performing weighted fusion on the external multi-source intelligence data based on the update credibility weight to generate an external comprehensive threat score; finally, obtaining target threat intelligence data based on the enhanced intelligence data and the external comprehensive threat score, so that accurate data support can be provided for a defense system, and high-value security decisions can be effectively assisted.
Owner:PENG CHENG LAB

Rapid matching selection method for electric-thermal collaborative strategy

PendingCN121563138AOffice automationTargeted threatReliability engineering
The invention discloses an electric-fire cooperation strategy rapid matching selection method, which aims at an electric-fire cooperation problem, combines obtained combat data to generate a target threat degree level, and realizes autonomous electric-fire rapid matching cooperation based on strategies under different tasks and specific capabilities of a fire platform. The method can provide support for evaluation and analysis of combat.
Owner:NO 8511 RES INST OF CASIC

A threat intelligence fusion method and device, electronic equipment and storage medium

ActiveCN115643094BSecuring communicationData miningTargeted threat
The application provides a threat intelligence fusion method and device, electronic equipment and storage medium. The method comprises the following steps: acquiring a plurality of threat intelligence data to be fused, wherein the intelligence values of the threat intelligence data to be fused are all target intelligence values; determining the threat intelligence data to be fused as target threat intelligence data, wherein the intelligence source confidence value of the threat intelligence data to be fused is greater than a first threshold value; for each judgment type, performing data fusion processing on the judgment value corresponding to the current judgment type in each target threat intelligence data, so as to obtain a fused judgment value corresponding to each judgment type; and generating fused threat intelligence data according to the target intelligence value and each fused judgment value. In the application, if the same intelligence value has a plurality of corresponding threat intelligence data to be fused, the method provided by the application can screen out the fused threat intelligence data with higher accuracy and after fusion processing, so that when the threat intelligence data is used subsequently, how to use can be determined directly according to the fused threat intelligence data corresponding to the intelligence value.
Owner:HARBIN ANTIY TECH

Ebpf and xdp based ipv6 fragmentation bypass threat detection method and system

The application relates to the technical field of network security, in particular to an IPv6 fragmentation bypass threat detection method and system based on eBPF and XDP, which sets a data packet observation point at a network driver layer, the data packet observation point is used for mounting an extended Berkeley packet filter (eBPF) program on a data packet processing path by using a fast data path (XDP) technology; for a data packet received on the network driver layer, the data packet observation point calls the eBPF program on an XDP network hook, the eBPF program is used for identifying and filtering a data packet with potential threats by using a feature matching strategy, the feature matching strategy is used for extracting key features of the data packet, matching the extracted key features of the data packet with target threat features, and judging whether an upper layer header of the data packet is complete; the application realizes efficient detection of specific threats by combining the dynamic programmability of the eBPF and the high-performance data packet processing capability of the XDP, meets the task requirements of an IPv6 network security threat high-performance solution, and has a smaller influence on system stability even under serious threats.
Owner:Chinese People's Liberation Army Cyberspace Force Information Engineering University

An abnormal traffic data generation method, device, equipment and medium

PendingCN122457348AData sourceData mining
The application discloses an abnormal traffic data generation method and device, equipment and medium, and relates to the field of network security, comprising: constructing a structured knowledge base; the structured knowledge base comprises a network topology knowledge base and a threat intelligence knowledge base, the network topology knowledge base is constructed based on information extracted from a preset network topology data source, and the threat intelligence knowledge base is constructed based on information extracted from a preset threat intelligence data source; a generative pre-training model is used as a base model, and the base model is fine-tuned based on the network topology knowledge base and the threat intelligence knowledge base in sequence to obtain a fine-tuned model; a target network topology description and a target threat intelligence description are input into the fine-tuned model to obtain abstract packet descriptions that meet topology constraints corresponding to the target network topology description and semantic requirements corresponding to the target threat intelligence description and output by the fine-tuned model; and the abstract packet descriptions are converted into executable physical network packets and output as abnormal traffic data.
Owner:PENG CHENG LAB

Security quality evaluation device, security quality evaluation system, security quality evaluation method, and security quality evaluation program

PCT designated stageWO2026042291A1Platform integrity maintainanceCountermeasureTargeted threat
A zone model generation unit (112) has a first axis for a countermeasure value serving as an index of the number of countermeasures to be applied to security threats, and a second axis for a threat value serving as an index of the number of threats to be dealt with, and generates one or more zone models in which a space formed by the first axis and the second axis is divided into a plurality of zones and a security opinion is set for each zone. A zone analysis unit (113) identifies a target countermeasure value and a target threat value on the basis of countermeasure threat information of one or more evaluation targets, and acquires an opinion corresponding to a set of the target countermeasure value and the target threat value from the zone model as a quality opinion for the quality of security of the evaluation target.
Owner:MITSUBISHI ELECTRIC CORP

A multi-state target threat assessment and collaborative management method for low-altitude economy

PendingCN122454790AData setCountermeasure
The application discloses a kind of multi-state target threat assessment and collaborative management methods for low-altitude economy, with situation base map as global data set, low-altitude target is divided into compliance, transition state and non-compliant three states and implements unified control, when the target broadcast effective RID has held VID, identity trusted merging is realized by double track tracking and merging consistency comparison;Threat assessment adopts the double-channel architecture of data-driven and expert rule parallel, with compliance deviation degree as common input;When generating evasion route for compliance and transition state target, the evasion route is written into flight plan database as temporary equivalent authorized route synchronously, so that threat assessment calculates deviation according to updated reference route, thereby avoiding evasion behavior being misjudged as route deviation. Before executing countermeasure, compliant targets and transition state targets in the influence domain are identified and disposed by linkage effect prediction, evasion instructions are issued to them first and then execution is disposed, to realize differentiated collaborative management.
Owner:JIANGSU POLICE INST

Network security assessment method and device, storage medium and program product

The invention discloses a network security assessment method and device, a storage medium and a program product, and the method comprises the steps: carrying out the network connection of a plurality of asset nodes based on an attack technology chain, and obtaining a plurality of attack paths; under one or more threat levels, performing protection evaluation on each attack and defense scene in one or more attack and defense scenes corresponding to each attack path based on the multi-source data to obtain a protection success rate of each attack and defense scene under each threat level; based on the protection success rate of one or more attack and defense scenes corresponding to each attack path under each threat level, performing quantitative evaluation on each attack path to obtain the path accessibility of each attack path under each threat level; performing comprehensive quantification processing on the path accessibility of each attack path under each threat level to obtain a target threat defense level; wherein the target threat defense level represents the highest threat level effectively defended in the network security protection system.
Owner:MIGU CO LTD +1