Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

448 results about "Threat" patented technology

In computer security, a threat is a possible danger that might exploit a vulnerability to breach security and therefore cause possible harm. A threat can be either "intentional" (i.e. hacking: an individual cracker or a criminal organization) or "accidental" (e.g. the possibility of a computer malfunctioning, or the possibility of a natural disaster such as an earthquake, a fire, or a tornado) or otherwise a circumstance, capability, action, or event.

Systems and methods for analyzing cybersecurity threat severity using machine learning

A method for cybersecurity threat actor severity scoring, the method comprising: receiving public data that includes publicly available information obtained via monitoring of a data connection between one or more networks; parsing first data related to a cybersecurity event from the public data; associating the first data with a first threat actor; obtaining second data that includes information regarding one or more previous cybersecurity events associated with the first threat actor; determining a first threat actor score based on the first data and the second data; receiving a second threat actor score for a second threat actor; causing a graphical user interface to display a graphical depiction of a ranking of the first threat actor and the second threat actor based on the first threat actor score and the second threat actor score.
Owner:CAPITAL ONE SERVICES LLC

Systems and methods for real-time generation and execution of computer-executable investigative queries in a cybersecurity event detection and response platform

A system, method, and computer-implemented method includes generating a security alert for a subscriber, executing an automated investigation protocol for the security alert, obtaining, in response to executing a first plurality of computer-executable investigation queries and a second plurality of computer-executable investigation queries, a corpus of investigation findings data indicative of whether the security alert corresponds to a security threat or a benign security alert, and displaying, using a graphical user interface, the security alert in association with the corpus of investigation findings data.
Owner:EXPEL INC

An asset emulation system for threat awareness

The application provides an asset simulation system for threat awareness, comprising a simulation module, a decision module, a semantic mapping library, a response agent, a resource storage module and a session library, when an access request of an attacker is received, the decision module first matches the resource type corresponding to the request through the semantic mapping library, if it is static resource access, the decision module directly calls the static simulation resource in the resource storage module and returns the response, if it is dynamic resource access, the decision module triggers the response agent, so that the response agent is started and dynamically interacts with the attacker, records the interaction log, and synchronously updates the session context to the session library. The application realizes high-fidelity replication of static and dynamic resources of the protected assets relying on a vertical large model, and through hierarchical design, can quickly respond to static resource access and deeply interact with dynamic resource access.
Owner:GUANGZHOU UNIVERSITY

A database security system and its management method

PendingCN122333455ADigital dataAttack
This invention provides a database security system and its management method, relating to the field of electronic digital data processing technology. The invention aims to address the problems of existing database security technologies, which suffer from insufficient ability to identify complex and covert attacks and a high false alarm rate due to their single monitoring dimension and lack of cross-domain correlation analysis capabilities. By introducing an innovative cross-domain anomaly collaborative analysis mechanism, this invention can achieve synchronous cross-verification of attack "intent" and attack "methods," thereby significantly improving the predictive identification capability and accuracy of advanced threats while greatly reducing security false alarms caused by normal business fluctuations or system jitter, thus enhancing the intelligence level and reliability of the entire database security system.
Owner:WEIFANG ZHONGSUO INFORMATION TECH CO LTD

A network security threat analysis method, device, equipment and medium

This application discloses a network security threat analysis method, apparatus, device, and medium, relating to the field of network security. The method includes: acquiring the current adjudication log output by a mimicry device; determining the target scheduling log associated with the current adjudication log based on a preset log association technique; ensuring that the current adjudication log and the target scheduling log are generated under the same event flow; scoring the credibility of the current adjudication log based on the target scheduling log and several target disturbance factors of current executors to obtain a target credibility score; evaluating the target credibility score using preset credibility evaluation rules, and determining whether to issue an early warning based on the evaluation result, thereby achieving network security threat analysis. It is evident that this application achieves log association between different mimicry devices through a preset log association technique, further providing a strong guarantee for the credibility measurement of adjudication logs, thus greatly enhancing the network's security defense capabilities.
Owner:PURPLE MOUNTAIN LAB +1

A power network vulnerability analysis system and method based on virtual attack and defense deduction

The application discloses to the technical field of power network, specifically is a kind of power network vulnerability analysis system and method based on virtual attack and defense deduction, comprising: data acquisition module, for responsible collection various data of power network, the various data include network topology structure data, equipment configuration data, operating state data, security log data;Threat intelligence integration module is used to collect, integrate network security threat intelligence from the world, and with threat intelligence platform establishes data interface, realizes the automatic synchronization and update of threat intelligence.The application can simulate new attack means, monitor power network security state in real time by continuous virtual attack and defense deduction, combined with machine learning algorithm optimization attack and defense strategy.Even if there is unprecedented attack mode, the application can quickly identify potential threats through attack and defense confrontation, greatly improve the discovery ability of new and unknown vulnerabilities, and respond to network security risks in time.
Owner:CEPO BEIJING INFORMATION TECH CO LTD +1

Cybersecurity event handling and enrichment system

A Cybersecurity Event Handling Processor (CEHP) and method for processing security alerts includes: a File System containing a Universal Target Schema (UTS) of target language representations (UTS JSONs); a Normalizer running Feature Extraction and Word Embeddings algorithms; a Tree Converter; and a Transformer running linguistic and structural matching algorithms. The CEHP: (a) captures threat events in one or more native formats generated by cybersecurity tools; (b) runs Feature Extraction and Word Embeddings algorithms for tokenization and categorization of the captured events to create normalized events; (c) converts the normalized events into trees and then translates the trees into event representations in JSON (or XML) format (Event JSONs); and (d) runs nearest neighbor and / or linguistic and structural matching algorithms to compare the Event JSONs to the UTS JSONs to generate output JSONs (Translation JSONs) from the UTS corresponding to the captured events.
Owner:NUHARBOR SECURITY INC

System and method for generating dynamic cyber threat models based on application architecture

A system includes a memory configured to store a set of application environment parameters associated with a software application of a plurality of software applications. The system further includes processors for accessing the set of application environment parameters associated with the software application, identifying, based on the set of application environment parameters, a plurality of potential threats and vulnerabilities associated with an execution of the software application in accordance with the current configuration, and executing one or more generative machine-learning models trained to generate a prediction of one or more cyber threat scenarios based on the set of application environment parameters and the plurality of potential threats and vulnerabilities. The prediction of the one or more cyber threat scenarios includes cyber threat scenarios specific to the software application. The processors further output, by the one or more generative machine-learning models, the prediction of the one or more cyber threat scenarios.
Owner:BANK OF AMERICA CORP

A method for security threat perception and detection of global network devices

ActiveCN121841825BInternet trafficAttack
This invention discloses a security threat perception and detection method for global network devices. It simultaneously collects three types of data: network traffic, behavior logs, and attack characteristics, forming multi-dimensional factual evidence. The method utilizes a firework algorithm to optimize the deployment of logical monitoring points (feature nodes) in the virtual network and calculates the dynamic intensity of threat propagation at each point, thereby constructing a node-level threat field that quantifies the spatial distribution of threats. Subsequently, peak, mean, and dispersion indicators are extracted, and behavioral load, threat polarization, and cumulative threat indicators are calculated from the raw data, forming a six-dimensional vector. This vector is input into a pre-trained global threat level classification model, outputting a discrete threat level. Finally, based on this level, firewall rules, intrusion detection feature libraries, and other protection strategies are dynamically adjusted to achieve automatic matching of security configuration and threat posture.
Owner:BEIJING SHANGZHANG INFORMATION TECHNOLOGY CO LTD

A system and a method for data protection assessment using threat modeling and adaptive optimization

A system and a method for data protection assessment using threat modelling and adaptive optimization is disclosed. The system (100) comprising a processor (105) and memory (110) with instructions to receive a data access request (345) from entities (120) via authenticated digital interface (125) including structured and unstructured data categories (350), metadata parameters (355), initiating contextual analysis to establish baseline compliance parameters (360). The system analyses data category and metadata using adaptive classification logic and correlation metrics across stored data lineage, distinguishing privacy -critical from non- sensitive data. Threat modelling (130) evaluates correlations among privacy attributes (365), metadata, operational parameters, and regulatory requirements to identify vulnerabilities (375) and exposure points. A composite risk index (135) is derived, forming a structured risk profile (140) with quantified scores (380). Compliance recommendations (150) are generated, safeguard parameters (155) are derived, authorization validated by a compliance authority (160), and a compliance trace (388) is recorded.
Owner:PRIVASAPIEN TECH PTE LTD

Railway signal system based on trusted computing security computing protection technology

PendingCN122113178AAutomatic systemsUser identity/authority verificationTelecommunications linkTrusted Computing
The application discloses a kind of railway signal system security computing protection technology and system based on trusted computing.The application takes hardware trusted module as trust root, constructs the end-to-end trusted verification chain covering operation and maintenance terminal, communication link and destination device;Through the trusted management platform of center, the trust measurement and white list management of operation and maintenance tool are realized;Deeply integrate railway "window time" and standard operation process, construct device dynamic trusted benchmark model, and generate operation and maintenance personnel behavior trusted model based on historical behavior data;Deploy lightweight trusted agent to monitor operation and maintenance behavior in real time, and implement hierarchical response and authority control to behaviors deviating from the two models.The application realizes dynamic trusted protection in the whole operation and maintenance process, effectively improves the active defense capability against internal and external threats, balances safety strength and operation and maintenance efficiency, and provides business-aware security protection for railway signal system and key infrastructure.
Owner:CHINA STATE RAILWAY GRP CO LTD +1

Method for monitoring and enforcing secure policies in a device

ActiveUS12671707B2Security policyPacket filtering
A method for monitoring and enforcing secure policies in a device includes collecting kernel data from a kernel space by a packet filtering module operating in a user space. The kernel data is processed into events that are transmitted to a data bus, where the events are stored and provided to a policy enforcement module. The policy enforcement module evaluates the events with an algorithm to detect potential threat events. When a threat event is identified, one or more secure policies are selected and executed in the device as corresponding actions or commands. The method enables real-time monitoring of kernel activity and enforcement of security policies while maintaining the architecture in user space.
Owner:EXEIN SPA

A multi-dimensional security data fusion security management information early warning platform

The application is suitable for the technical field of informationized early warning platform, and provides a security management informationized early warning platform for multi-dimensional security data fusion, comprising: a multi-source data acquisition module, which is used for collecting multi-dimensional security data sources such as video monitoring data, sensor signals and network logs in real time; the platform collects multi-dimensional security data sources such as video monitoring data, sensor signals and network logs in real time through the multi-source data acquisition module, and combines cross-modal correlation analysis and feature extraction realized based on a self-adaptive attention mechanism of a data fusion module, so as to effectively integrate complementary information of heterogeneous data sources, overcome the defects that a single data source is susceptible to environmental interference, has a limited perspective or incomplete information, and provide reliable input for a risk early warning module with high-quality feature data after fusion, so that the platform can dynamically and accurately identify potential threats, and significantly improve the accuracy and recall rate of early warning.
Owner:中环低碳节能技术(北京)有限公司

Restricted execution mode for network-accessible devices

Various aspects related to methods, systems, and computer readable media for restricting processes being executed on a user device. A method can include, for example, receiving an indication of a security threat to a user device associated with a user, identifying a first plurality of processes being executed on the user device, identifying a second plurality of trusted processes from the first plurality of processes, receiving, from a remote device in operative communication with the user device, a command to terminate or suspend one or more processes from the first plurality of processes that are not in the second plurality of trusted processes, and, after the terminating or suspending, remediating the security threat on the user device.
Owner:SOPHOS LTD

A Knowledge Graph-Based Intelligent Method and System for Detecting Software Backdoors

This invention relates to the field of software detection technology, specifically disclosing a knowledge graph-based intelligent detection method and system for software backdoors. The method involves intercepting system kernel events and reading the object handle table to generate a time-series interaction log. Based on this log, a time-series knowledge graph is constructed, forming an interconnected network composed of process nodes, token nodes, and relationships such as handle holding, token replication, and memory writes. Newly added process nodes with process creation timestamps are further extracted as target process nodes, and the nominal parent process node is located based on its parent process identifier. Subsequently, a lineage consistency check is performed around the target process node, and cross-chain constraint analysis is conducted using the nominal parent process node, anonymous process nodes, token nodes, and memory write relationships. When contradictions arise in handle permissions, token inheritance, and write timing, and the lineage forgery index exceeds a preset threshold, the target process node is determined to be a parent process deceiving a backdoor process, and a threat interception command is output.
Owner:SHENZHEN HAIYUNAN NETWORK SECURITY TECH CO LTD

A large model threat sample library construction method

PendingCN122433830AEvaluation resultData mining
The application belongs to the technical field of large model security, and specifically discloses a large model threat sample library construction method, which comprises the following steps: step S1, embedding malicious instructions or malicious data into prompt words to construct threat samples; step S2, inputting the threat samples into a target large model as prompt words; step S3, using an evaluation large model to evaluate the output results of the target large model; and step S4, if the evaluation result is harmful content, adding the threat sample into a threat sample library, otherwise, discarding the threat sample. The application solves the problem of the lack of a threat sample library for security testing of an existing large model, and automatically tests and evaluates the threat samples during the construction of the sample library, so that the threat samples can be stored in the library only after the evaluation, thereby effectively improving the construction efficiency of the threat sample library. Meanwhile, the constructed threat sample library can support the security testing of the target large model, and can be used to improve the security of the target large model.
Owner:CHINESE PEOPLES LIBERATION ARMY UNIT 32802

Proactive browser content analysis

ActiveUS12688293B2Software engineeringContent analytics
A protection module operates to analyze threats, at the protocol level (e.g., at the HTML level), by intercepting all requests that a browser engine resident in a computing device sends and receives, and the protection agent completes the requests without the help of the browser engine. And then the protection module analyzes and / or modifies the completed data before the browser engine has access to it, to, for example, display it. After performing all of its processing, removing, and / or adding any code as needed, the protection module provides the HTML content to the browser engine, and the browser engine receives responses from the protection agent as if it was speaking to an actual web server, when in fact, browser engine is speaking to an analysis engine of the protection module.
Owner:OPEN TEXT CORPORATION

A method, apparatus, device and medium for network security incident analysis

PendingCN122293423ALinguistic modelIncident analysis
This application discloses a method, apparatus, device, and medium for network security incident assessment, relating to the field of computer technology. It is applied to a network security incident assessment system. The system deploys a large language model within an analysis chain framework to perform progressive reasoning. The method includes: extracting target assessment features related to network security threats from multi-source heterogeneous data; determining at least one threat hypothesis scenario based on the target assessment features; assigning positive weights to supporting evidence for the scenario and negative weights to rebuttal evidence for the scenario; performing reasoning analysis on the evidence set to generate a target assessment report for the threat hypothesis scenario; the evidence set is obtained based on target evidence carrying the aforementioned weights. This application avoids interference from different contextual scenarios in the judgment; avoids the problem of lack of reasoning basis in the reasoning process; significantly reduces misjudgments and omissions; and solves the problem of insufficient understanding and adaptability of general large language models to network security expertise.
Owner:SANGFOR TECH INC

Device for autonomous detection of cyber threats

A device for the autonomous detection of cyber threats, consisting of: a housing that encloses a multitude of interconnected hardware components; a network interface unit configured to receive and send data packets from one or more communication networks; a data acquisition unit that is operationally connected to the network interface unit and configured to capture packet-level data, metadata, and system event logs; a preprocessing processor configured to analyze captured data, decodecode protocols, reconstruct communication flows, and generate structured data representations; a feature extraction processor that is operationally coupled with the preprocessing processor and is configured to calculate statistical, temporal and entropy-based features from the structured data representations; a storage unit consisting of volatile memory for real-time processing and non-volatile memory for storing historical data and learned patterns; an inference processor that is operationally coupled with the feature extraction processor and the storage unit, wherein the inference processor is configured to execute a variety of trained models to identify anomalous behavior based on deviations from stored patterns; a classification unit that is operationally coupled with the inference processor and configured to assign detected anomalies to one or more threat categories based on calculated confidence values; a response control unit configured to generate and transmit remedial actions, including blocking network traffic, isolating network segments, and terminating suspicious processes; and a control processor configured to coordinate the data flow between the network interface unit, the data acquisition unit, the preprocessing processor, the feature extraction processor, the inference processor, the classification unit, the response control unit, and the storage unit, with the device operating autonomously to detect and respond to cyber threats in real time.
Owner:ALMOMANI DUAA SHAWKAT +1

Systems and methods for formal verification of computer platforms

Systems and methods for mathematical modeling of the hardware and software stack of commodity computer platforms are provided, enabling provable guarantees on memory, device, and program execution. This approach addresses the technical problem of reliance on system agents that rely on implicit trust in the operating environment, which can be exploited by sophisticated attackers using complex threats such as memory access exploits and code / data integrity exploits. The solution provides a proactive, mathematically-backed security solution that eliminates entire classes of cyberattacks by design, ensuring realizable guarantees on commodity computer platforms running hardware and software stack elements at the lowest operating level. This approach has significant advantages over current reactive cybersecurity methods, including reduced complexity and overhead, and increased confidence in the integrity of the system. The solution's main uses include providing mathematically-backed security and availability guarantees for critical infrastructure, financial institutions, and other organizations vulnerable to cyberattacks.
Owner:UBERSPARK INC

A network security browsing system and method

PendingCN122316703AWeb siteInternet content
This invention discloses a network security browsing system and method. First, a user request forwarding module sends user requests to an RBI server, with all subsequent interactions completed on the RBI server. This achieves physical isolation between the user's local device and internet content, preventing direct attacks from malicious websites and ensuring user access security. Second, a request analysis and processing module performs in-depth analysis of the content and destination of user requests, proactively identifying and intercepting potential threats such as phishing websites and malicious code injection, compensating for the shortcomings of traditional technologies in ensuring website content security. Third, when the target website is secure, the content acquisition and presentation module allows the RBI server to request and process content in a secure environment, making it difficult for malicious code to cause damage and preventing attacks on the system. All modules work together to create a safe and reliable network browsing environment for users.
Owner:GUANGZHOU NENGCHUANG INFORMATION TECH CO LTD

Deep learning based network threat detection and response system

The application relates to the technical field of network threat detection, and discloses a network threat detection and response system based on deep learning. The system comprises a collection module, a statistical module and an instruction generation module. The collection module is used for collecting standardized data sets from a plurality of preset security areas. The statistical module is used for statistically calculating attack equivalent cumulative values, defense strength indexes and asset attack exposure degrees based on the standardized data sets. The instruction generation module is used for calculating a threat comprehensive score according to the attack equivalent cumulative values, the asset attack exposure degrees and the defense strength indexes, and generating blocking instructions, isolation instructions and flow limiting instructions according to the threat comprehensive score. The application can automatically generate an access control strategy according to an attack chain analysis result and execute the access control strategy, thereby forming a complete closed loop from threat detection to strategy optimization, and improving the synergy, accuracy and real-time performance of network security operation.
Owner:SHENZHEN ZHIHECHUANGWEI INFORMATION TECH CO LTD

Defence decision generation method and system facing dynamic threat situation and electronic equipment

The application discloses a kind of defense decision generation methods, systems and electronic equipment for dynamic threat posture, including dynamic threat posture modeling and defense knowledge base construction: target network topology, asset and threat event are structuredly described, dynamic threat posture representation is constructed, and defense knowledge graph is formed in combination with defense rule, response action and security constraint;Multi-stage decision strategy generation based on defense large model: based on defense knowledge graph, introduce defense large model as core reasoning engine, defense process is divided into multiple defense stages, and candidate defense strategy sequence is generated in each stage;Strategy evaluation feedback and closed-loop dynamic optimization output: candidate defense strategy is multidimensional evaluated, and constraint condition is dynamically adjusted according to execution feedback, strategy regeneration is triggered, and closed-loop defense decision mechanism is formed to output the sustainable optimization of strategy.The method of the application can significantly improve the automated defense decision capability under complex network environment.
Owner:HARBIN INSTITUTE OF TECHNOLOGY (SHENZHEN) (INSTITUTE OF SCIENCE AND TECHNOLOGY INNOVATION HARBIN INSTITUTE OF TECHNOLOGY SHENZHEN)

Security threat processing method and apparatus, terminal, and computer-readable storage medium

The embodiment of the application discloses a kind of security threat processing method, device, terminal and computer readable storage medium, the method comprises: monitoring to abnormal behavior log, determine the security processing large model workflow for abnormal behavior log;Security processing large model is used according to security processing large model workflow to carry out security threat processing to abnormal behavior log;Monitoring security processing large model in the current security processing stage of security processing large model workflow, by intelligent security digital object service output the large model workflow explanation information corresponding to current security processing stage.Can solve the technical problem that conventional security threat processing software is difficult to provide perceptible security threat killing process for enterprise like network security expert, so that enterprise is difficult to enhance the cognition of security threat in the process of processing security threat.
Owner:BEIJING HONGTENG INTELLIGENT TECH CO LTD

A method for implementing island network vulnerability scanning based on Metasploit technology

ActiveCN117040815BComputer networkAttack
The application discloses a method for realizing island network vulnerability scanning based on Metasploit technology, which comprises the following steps: setting an intermediate machine with traffic relay function in the island network; connecting to the intermediate machine from an external network and building a Metasploit environment on the intermediate machine; penetrating the intermediate machine by using modular components and related attack technology in the Metasploit and obtaining the access right to the internal island network; scanning the host and running service in the island network by using the vulnerability scanning module in the Metasploit and transmitting the scanning result back to the intermediate machine. The method can discover and repair the possible security vulnerability in the island network, can comprehensively and deeply scan the island network, can flexibly scan the vulnerability and manage the security of the island network from the external network, and can transmit the scanning result back to the intermediate machine in real time to deal with the possible security threat in time.
Owner:YUNNAN POWER GRID CO LTD

A method and system for defense of heterogeneous security devices based on control computing

This invention relates to the field of network security technology and provides a method and system for defending heterogeneous security devices based on management and control computing. By constructing a device adaptation module to uniformly manage heterogeneous security devices and converting multi-source monitoring data into standardized event data, a fusion threat identification is performed using a detection model composed of a concatenated convolutional neural network and a long short-term memory network, which includes a penalty term for differences in cross-device threat prediction probability distribution. Dynamic defense actions are generated based on a Q-value table combined with network status. Attack paths are inferred through security entity association networks, and strategies are calibrated. Dynamic priority is applied according to threat confidence and target value level, with closed-loop optimization. This solves the problems of isolated defenses, rigid strategies, and delayed response of heterogeneous security devices, achieving dynamic collaborative detection and linked defense of heterogeneous devices, improving threat response speed and resource utilization efficiency.
Owner:SHENZHEN Y& D ELECTRONICS CO LTD

Threat exposure management system using large language models

A system and method of using generative AI to identify exposures of computing devices on computing networks to actual and / or potential threats. The method includes collecting a plurality of responses from a plurality of devices to a target device on a private network. The method includes providing the plurality of responses to a classification model trained to assign device descriptions for device responses based on semantic matching of the device responses to database data. The method includes assigning, by the processing device using the classification model, a plurality of device descriptions for the plurality of responses to the target device, each response is respectively associated with one or more device descriptions of the plurality of device descriptions. The method includes generating, based on the plurality of device descriptions, a status report comprising a list of network addresses associated with a group of devices having access to the target device.
Owner:CROWDSTRIKE

Large language model self-adaptive security protection method and system, and storage medium

PendingCN122457379ALinguistic modelAlgorithm
The application provides a large language model adaptive security protection method and system, and a storage medium, the method breaks the hysteresis of the traditional defense strategy by constructing a three-agent collaborative architecture of an attack strategy generator, a dynamic defense device and a defense and attack environment evaluator, combining a double-layer optimization and a dynamic evolution mechanism, driving a two-way iteration relying on attack and defense utility quantitative scores, and synchronously evolving the defense capability and the attack evolution; the method constructs a double-layer defense capability for coping with the current situation and predicting the future by real-time adaptation of the defense parameters to the current attack and pre-judgment of the new attack by the defense parameter, improves the generalization to unknown attacks; the method strengthens the learning and identification of high uncertainty attacks by combining meta-learning attack evolution and threat entropy weighted loss, reduces the bypass probability of new attacks; the method balances the security and usability of the large language model by using a dynamic threshold judgment, realizes adaptive and highly reliable security protection in an open scene, and has better generalization.
Owner:SHENZHEN SHENNONG INFORMATION TECHNOLOGY CO LTD