Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

3973 results about "Threat" patented technology

In computer security, a threat is a possible danger that might exploit a vulnerability to breach security and therefore cause possible harm. A threat can be either "intentional" (i.e. hacking: an individual cracker or a criminal organization) or "accidental" (e.g. the possibility of a computer malfunctioning, or the possibility of a natural disaster such as an earthquake, a fire, or a tornado) or otherwise a circumstance, capability, action, or event.

System for detecting malicious nodes in a wireless sensor network and a method thereof

The present disclosure generally relates to a two-stage system for detecting malicious nodes in Wireless Sensor Networks (WSNs), enhancing network security and resilience. The system employs a distributed approach, leveraging Cluster Heads (CHs) and a central server for efficient and accurate detection. Initially, sensor nodes are monitored for comprehensive node and network metrics, statistically ranked by significance in identifying malicious behavior. CHs perform a resource-aware first-stage detection based on their resource weight, filtering potential threats locally. Results are then aggregated at a server for a second-stage analysis using a hybrid Machine Learning (ML) and Deep Learning (DL) approach. This advanced analysis, combined with statistically relevant metrics, significantly improves detection accuracy. By integrating resource-conscious CH operation with powerful server-side ML / DL, this system offers a scalable, energy-efficient, and highly effective solution for securing WSNs against malicious node attacks, surpassing traditional detection methods in both speed and precision.
Owner:KHASHAN OSAMA AHMED

Network security space surveying and mapping method, system and equipment based on multi-source data fusion

The invention relates to the field of security surveying and mapping, in particular to a network security space surveying and mapping method, system and device based on multi-source data fusion, and the method comprises the steps: obtaining network security data in real time, and constructing a dynamic network topological graph; calculating a time-varying vulnerability score based on the topological graph and a historical attack log, and predicting an attack path and a propagation probability through a Bayesian network; performing cross-domain fusion on equipment, service and user behavior characteristics by adopting a federated learning framework to generate a dynamic asset portrait; generating a risk thermodynamic diagram in combination with spatial autocorrelation analysis and a multi-index fusion algorithm; a defense strategy effect is simulated based on an attack graph reconstruction engine, a Pareto optimal strategy combination is generated through an NSGA-II algorithm, and closed-loop verification and dynamic parameter correction are realized by utilizing honeypot deployment and flow traction. Therefore, the problems of topology update lag, single risk assessment dimension, cross-domain threat association fracture, defense strategy static stiffness, non-closed loop of a verification system and the like in the traditional technology are solved.
Owner:ELECTRIC POWER SCI RES INST OF STATE GRID XINJIANG ELECTRIC POWER CO LTD

Ai-based cybersecurity system and method thereof

An AI-based Cybersecurity System and Method enable real-time detection, analysis, and mitigation of cyber threats within computing networks using adaptive artificial intelligence. The system continuously monitors network traffic, extracts behavioral and contextual attributes, and applies deep learning-based inference to identify anomalous activities indicating security breaches. The method integrates several computational units, including a network monitoring unit, feature extraction unit, artificial intelligence processor, contextual reasoning processor, and decision synthesis unit, to compute a composite risk index quantifying threat likelihood and severity. A classification processor categorizes detected threats into types such as ransomware, phishing, or unauthorized access, while a mitigation control processor initiates automated response actions to isolate compromised nodes and restore network integrity. An adaptive learning processor updates AI models using feedback from confirmed incidents. This provides a scalable, self-evolving cybersecurity framework that minimizes human intervention and enhances resilience against dynamic and zero-day threats.
Owner:PELL REDDY RAJENDER REDDY

Bank medical intelligent terminal data secure transmission and real-time management and control system and method

The invention relates to the technical field of medical terminal data secure transmission and real-time management and control, in particular to a bank medical intelligent terminal data secure transmission and real-time management and control system and method. The behavior analysis module is used for calculating threat indexes through federated learning, the strategy module is used for dynamically switching algorithms and isolating anomalies, and the audit module is used for block chain verification and zero knowledge verification to generate a report. According to the method, dynamic encryption and fragmentation cutting are driven through sensitivity grading labels, the accuracy of data protection is improved, a time sequence attack path is blocked based on cooperation of fragmentation time sequence reference and an encryption transmission protocol, and dual guarantee of decentralized auditing and tampering positioning is realized by combining block chain hash identification and zero-knowledge proof verification, so that the security of data protection is improved. And full-link safe transmission and real-time management and control requirements of medical terminal data are met.
Owner:SHANGHAI SHUZHI MEDICAL TECHNOLOGY CO LTD

Network security protection method and system applied to regional digital and intelligent asset business

The invention provides a network security protection method and system applied to regional digital and intelligent asset businesses, and the method comprises the steps: collecting asset data flows of a plurality of asset business nodes in a target region, carrying out the threat feature extraction of the asset data flows based on a preset threat knowledge graph, and obtaining a threat feature extraction result; generating a dynamic threat feature vector corresponding to the asset service node; inputting the dynamic threat feature vector into a pre-trained dynamic protection model, and outputting a real-time protection strategy adaptive to the asset service node through a multi-layer decision network in the dynamic protection model; performing strategy execution on the network flow of the asset service node based on the real-time protection strategy, generating a strategy execution result and feeding back the strategy execution result to the dynamic protection model; and performing adaptive optimization on decision parameters of the dynamic protection model according to a strategy execution result, and generating an updated dynamic protection model for a protection decision of a next round of asset business nodes.
Owner:GUIZHOU ANRONG TECH DEV CO LTD +1

Industrial control network security advanced threat detection system fused with artificial intelligence

The invention provides an industrial control network security advanced threat detection system fused with artificial intelligence. The system comprises a multi-source data acquisition module, an intelligent analysis engine, a threat detection module, a dynamic defense module and a self-evolution learning system which perform data interaction in sequence. The industrial control network security advanced threat detection system fused with artificial intelligence realizes collaborative decision-making among the modules through a dynamic knowledge graph. Through multi-source data fusion, dynamic knowledge graph and lightweight model design, the core problems of protocol analysis, threat association, defense collaboration and model adaptability in the industrial control network security field are solved, and a full-stack protection system covering'perception-analysis-decision-response-evolution 'is constructed. The deep analysis capability of an industrial protocol is improved, the dynamic threat association analysis is broken through, the agility of a defense strategy is enhanced, and the feasibility of continuous optimization of a model is improved, so that a systematic solution is provided for advanced threat defense in a complex industrial control environment.
Owner:CPI NORTHEAST ENERGY SAVING TECH

Flow analysis and threat detection method and device based on machine learning

The invention provides a flow analysis and threat detection method and device based on machine learning, and the method comprises the steps: collecting a real-time flow data package of a target network environment, carrying out the protocol analysis and session recombination, and generating a real-time flow feature data set containing multi-dimensional flow features; loading a pre-trained multi-level threat classification model, inputting the real-time traffic feature data set into a feature extraction layer of the model, carrying out normalized coding on traffic features of corresponding dimensions through feature coding channels, generating a real-time feature vector sequence, inputting the real-time feature vector sequence into a primary classifier of the model, and classifying the real-time traffic features according to the real-time feature vector sequence; and performing abnormal probability calculation and cluster division on the real-time feature vector sequence through a mixed detection unit, outputting a primary threat tag and an abnormal confidence coefficient corresponding to each real-time feature vector, inputting the primary threat tag and the abnormal confidence coefficient into an aggregation classifier, performing dynamic weighted aggregation, and generating a comprehensive threat score so as to judge whether a threat response strategy is triggered or not. According to the invention, the accuracy and timeliness of threat detection in a complex network environment can be improved.
Owner:FUZHOU PUBLIC SECURITY BUREAU +1

Exposure and Attack Surface Management Using a Data Fabric

The disclosed embodiments provide systems and methods for continuous exposure and attack surface management using a data fabric. Data from multiple heterogeneous cybersecurity sources, including vulnerability scanners, threat intelligence, cloud security tools, and endpoint monitoring systems, is ingested and integrated into a semantically harmonized representation, such as a security knowledge graph. This unified data model normalizes, correlates, and contextualizes diverse cybersecurity information, enabling comprehensive and real-time assessment of an organization's cybersecurity risk posture. Automated workflows trigger proactive remediation actions based on dynamically calculated exposure metrics. Additional embodiments leverage the same data fabric architecture to support specialized cybersecurity use cases, including unified vulnerability management (UVM), cyber asset attack surface management (CAASM), continuous threat exposure management (CTEM), and asset exposure management (AEM).
Owner:AVALOR TECH LTD

Network attack dynamic detection and security protection method and system based on artificial intelligence

The invention relates to the technical field of network attacks, in particular to a network attack dynamic detection and security protection method and system based on artificial intelligence, and the method comprises the following steps: S1, data collection: collecting a multi-protocol communication data flow of network equipment, and generating a multi-dimensional feature vector; s2, constructing a cross-protocol behavior graph: generating a dynamically updated network behavior graph; s3, anomaly detection: identifying an abnormal behavior mode through the deep residual sequential network, and outputting threat evaluation parameters; s4, protection strategy generation: generating a dynamic protection instruction set through a reinforcement learning decision algorithm; and S5, protection execution: executing the dynamic protection instruction set to complete safety protection operation. According to the method, the multi-protocol fusion behavior graph is constructed, and an abnormal detection mechanism of graph nerve and differential modeling and a dynamic response strategy driven by reinforcement learning are introduced, so that high-precision identification and efficient protection of network attacks are realized.
Owner:TIBET LANGJIE INFORMATION TECH CO LTD

Computer network information security monitoring method, system, equipment and medium

The invention relates to the technical field of network security, in particular to a computer network information security monitoring method, system and device and a medium, and the method comprises the steps: obtaining encrypted traffic data and application log data in a network environment, and constructing a space-time associated original data set based on the encrypted traffic data and the application log data; performing protocol analysis on the original data set with the time-space association to generate a protocol fingerprint feature vector; inputting the protocol fingerprint feature vector and the application log data into a preset heterogeneous multi-modal analysis model, and obtaining a multi-dimensional security situation assessment result containing a threat level and an attack path; and based on the multi-dimensional security situation assessment result, generating a dynamic defense strategy instruction set through a reinforcement learning algorithm, and issuing a strategy instruction to a network execution node in real time. The method and the device have the effects of realizing real-time accurate detection of encryption threats and constructing a dynamic defense system with balanced security and efficiency.
Owner:李俊磊 +1

Security Methods and Systems for Multi-Agent Generative AI Applications

A system and method for securing inter-process communications (IPCs) between generative AI and external tool servers, including intercepting IPCs having a requested operation, performing a security analysis on the IPCs for security threats, performing a permission validation for permissions for the requested operation of each IPC, and either approving or blocking the requested operation of each IPC based on the security analysis and the permission validation.
Owner:MADISETTI VIJAY

Artificial intelligence network security system based on multi-modal large model training

The invention relates to the technical field of intelligent security operation and maintenance, in particular to an artificial intelligence network security system based on multi-modal large model training, which comprises a server fault diagnosis module, a network attack detection module, an endpoint security monitoring module, a key management optimization module and a threat analysis feedback module. According to the method, the fault prediction accuracy is improved through multi-dimensional data analysis, service interruption caused by sudden hardware faults is reduced, the network access frequency, source and instruction features are evaluated based on the server abnormality, the attack detection accuracy is improved, the misjudgment risk is reduced, the endpoint equipment execution behavior, resource calling and behavior sequence are extracted, and the service performance of the terminal equipment is improved. Fine-grained security monitoring is realized, attack traceability is enhanced, a key strategy is dynamically adjusted, security adaptability is improved, strategy lag risk is reduced, multi-level data is integrated to calculate threat behavior and attack fitting degree, threat assessment fineness and response speed are enhanced, and global security situation awareness is improved.
Owner:SHENZHEN JINCHAO CLOUD CONTROL TECH CO LTD

Information security analysis method and system based on big data

The invention relates to the technical field of information security data processing, and discloses an information security analysis method and system based on big data, and the method comprises the steps: S1, collecting multi-source heterogeneous security related data which comprises a business log, a user behavior track, network traffic, an application program interface calling record, an identity authentication log and a real-time security data flow, preprocessing the collected data to obtain standardized data; and S2, performing entity identification, event extraction and relationship mining based on the standardized data, and constructing a cross-modal threat knowledge graph containing security entity nodes and associated edges. The method solves the problem of monitoring blind areas caused by lack of dynamic association mining capability among data in a traditional method, and particularly aims at distributed, low-frequency and multi-stage hidden attacks, the scheme can accurately recover an attack chain and identify high-risk threats through dynamic matching and path reasoning of a knowledge graph, and the method has a good application prospect. And the detection coverage rate and accuracy in a complex attack scene are remarkably improved.
Owner:BEIJING YUANFANG TIMES TECHNOLOGY CO LTD

Multi-defense-area intelligent linkage alarm method based on AIoT gateway and related equipment

The invention relates to a multi-defense-area intelligent linkage alarm method based on an AIoT gateway and related equipment, and the method comprises the following steps: fusing the environment data of an Internet of Things sensor of a plurality of defense areas with a video image stream to generate three-dimensional reconstruction data of a defense area scene; and monitoring and analyzing the data, and extracting an environment feature sequence and a trajectory analysis sequence. And when it is detected that the threat levels of the multiple defense areas exceed a threshold value, causal inference is carried out in combination with gateway historical alarm data, and a cross-defense-area association event chain is generated. According to the method and the system, the AIoT gateway is used as a core, then a cooperative response strategy preset by the AIoT gateway is matched, and the SP voice call module is linked through a 4G / 5G network, so that multi-channel alarm pushing is realized, and the technical problem that comprehensive understanding and dynamic modeling of a defense area scene are difficult to form due to the lack of deep fusion and cooperative analysis means between video image data and environment sensor data is solved.
Owner:SHENZHEN CETC CHENGAN TECH CO LTD

Network threat detection method and system

The invention relates to the technical field of intrusion detection, in particular to a network threat detection method and system, and the method comprises the following steps: building a threat path logic diagram through collecting field dependency items, action trigger timestamp items and action propagation hop count items of an attack behavior chain, and matching field dependency items among nodes based on a graph theory algorithm to obtain a threat path logic diagram; and detecting a mutual exclusion logic field combination, and generating a logic diagram structure with a connecting edge and a mutual exclusion mark. In the method, a threat path logic diagram is constructed by fusing field dependence, action timestamps and propagation hops, graph theory identification field mutual exclusion combination enhances cross-protocol attack chain analysis, and hidden Markov modeling state transition probability verifies time sequence continuity and path length. And performing dynamic time warping alignment on forward and reverse instruction sequences to extract semantic offset, overlapping rate and time sequence entropy, and performing non-linear score classification based on an isolated forest to detect an adversarial sample, topological structure analysis, time sequence verification, instruction alignment and non-linear classification to cooperatively identify a composite attack with field mutual exclusion and time sequence confusion.
Owner:JIANGSU SENDEBON INFORMATION TECH CO LTD +1

High-accuracy threat intelligence assisted network threat tracing method

The invention discloses a high-accuracy threat intelligence assisted network threat tracing method, which comprises the following steps: S1, collecting and preprocessing multi-source network security data, and constructing a time-marked event sequence set; s2, constructing an optimized Transform network model, and processing an attack event sequence by using position coding and time embedding; s3, a black swan optimization algorithm is initialized, and a Transform structure hyper-parameter is dynamically optimized; s4, outputting an attack event semantic vector, and constructing an attack path semantic map; s5, the intelligence information vector is embedded into a Transform hidden space; s6, calculating semantic similarity and dependency intensity, and generating an attack source candidate set and a traceability path; s7, outputting an attack traceability path, a starting point node and an information label, and generating a structured traceability report; and S8, according to the traceability result feedback, updating the black swan algorithm and the Transform model. The method is used for realizing intelligent modeling of multi-source network attack events and high-accuracy traceability analysis of attack source nodes.
Owner:GUANGXI POWER GRID CORP

Network security protection method and system based on information fusion

The invention provides a network security protection method and system based on information fusion, and the method comprises the steps: firstly obtaining a multi-source heterogeneous data set, which comprises a traffic interaction data unit, an equipment log data unit and a protocol analysis data unit, of a target network, then carrying out the time sequence correlation analysis of the traffic interaction data unit, and generating a traffic behavior feature set; and executing state mode analysis on the equipment log data unit to generate an equipment operation feature set, and executing semantic recognition on the protocol analysis data unit to generate a protocol analysis feature set. Then, on the basis of a multi-dimensional feature fusion rule, cross-dimensional feature fusion processing is carried out on the feature set, and a network situation feature set is generated; and calling a threat identification model to carry out threat identification on the set, generating a threat identification result set containing threat type identifiers and influence range parameters, and finally generating a security response strategy set according to the threat identification result and issuing the security response strategy set to a security control node to execute protection operation, thereby effectively improving the network security protection capability.
Owner:GUANGXI POWER GRID CORP

Network security threat research and judgment method, system and equipment and storage medium

The invention discloses a network security threat research and judgment method, system and device and a storage medium, and the method comprises the following steps: S1, obtaining network traffic, terminal logs, application program interface calling records and threat intelligence data in real time, carrying out the standardized cleaning and format conversion of the data, and building a unified data lake; s2, matching, identifying and determining threats through a preset known threat feature library, constructing a normal behavior baseline by using an unsupervised learning algorithm, and marking suspicious events deviating from the baseline; s3, for the suspicious event marked in the step S2, mining a potential attack path and an attack intention by combining knowledge graph technology associated asset information, a historical attack chain and a homologous IP address; and S4, based on the attack success probability, the influence asset importance and the diffusion speed, calculating a threat level by adopting a fuzzy comprehensive evaluation model, and generating a research and judgment report containing disposal suggestions.
Owner:CRCC DEV GRP CO LTD +1

Dynamic honey point collaborative intelligent threat trapping system and method based on genetic algorithm

The invention discloses a dynamic honey point collaborative intelligent threat trapping system and method based on a genetic algorithm in the technical field of network security, and the system comprises a multi-source information collection and dual-mode output module, a reinforcement learning strategy engine, a graph neural network prediction module, a digital twin simulation environment, a strategy verification and optimization module, and a real network defense execution module. A dynamic honey point deployment strategy is generated in real time through a reinforcement learning strategy engine, and the problem of strategy stiffness is solved; a third-generation non-dominated sorting genetic algorithm (NSGA-III) multi-objective optimization algorithm is used for coordinating honey point density adjustment, trip line sensitivity calibration and other actions; attacking path risks are quantified based on a threat scoring formula, digital twin environment pre-verification and high-risk node precise protection are driven, closed-loop linkage of threat perception, strategy optimization and active trapping is finally achieved, and the intelligent defense capability capable of achieving autonomous evolution is formed.
Owner:积至(海南)信息技术有限公司

Network security analysis early warning system based on artificial intelligence

The invention discloses a network security analysis early warning system based on artificial intelligence, and the system comprises a data collection layer which captures full flow based on DPI, aggregates firewall logs, terminal behaviors and threat intelligence, and constructs a structured data pool; through TLS fingerprint identification of AI driving, the encrypted traffic is penetrated, and a sampling strategy is dynamically adjusted in combination with reinforcement learning. The intelligent analysis layer is used for carrying out cross validation on known threats and abnormal behaviors; the time sequence CNN extracts encrypted traffic features, and a novel threat detector is rapidly generated by using historical attack fragments in combination with a meta-learning framework; sHAP value driving dynamic feature selection and optimization feature vector input; the decision-making early warning layer is used for fusing multi-source features through a Bayesian network and generating 0-100 score risk scores; a self-adaptive threshold module is combined to adjust a score threshold in real time, and a high-risk event is pushed; the collaborative response layer is used for triggering a preset decision tree, deploying a GAN dynamic honeypot to trap an attacker and reversely tracing; the Neo4j visually restores the attack path, and blocking is executed after the threat is confirmed by a progressive response mechanism.
Owner:CHINA GEOLOGICAL SURVEY XINING NATURAL RESOURCES COMPREHENSIVE SURVEY CENT

Network attack detection method based on dynamic graph coding

The invention belongs to the technical field of network security, provides a network attack detection method based on dynamic graph coding, and solves the problems of poor dynamic adaptability of an attack path and missing of timing constraint in the prior art. The method comprises the following steps: constructing a dynamic threat map, extracting a triple of heterogeneous threat intelligence by using a RoBERTa model, and adding a timestamp and a confidence attribute; a dynamic graph encoder for time sequence perception is designed, semantic and evolution laws are fused through periodic time coding and a multi-head time sequence attention mechanism, and feature weights are adjusted in combination with a gating residual layer; an event-driven incremental updating strategy is adopted, and node similarity is calculated to achieve local subgraph updating; a time sequence rule base is established, three-dimensional parameter verification attack chain time sequence logic is defined, and abnormity is judged through conflict scores; and finally, integrating a graph updating module, a dynamic coding module and a constraint analysis module to realize multi-source threat feature matching and attack detection. According to the method, the adaptability of attack path evolution is improved through dynamic graph modeling and real-time increment updating.
Owner:UNIV OF ELECTRONICS SCI & TECH OF CHINA

Zero-trust network dynamic access control method based on AI behavior portrait

The invention discloses a zero-trust network dynamic access control method based on an AI behavior portrait, and the method comprises the following steps: 1, collecting multi-source real-time behavior data during an access request; 2, constructing an AI behavior portrait engine based on historical data, inputting the integrated multi-source behavior data, calculating a behavior deviation degree through the AI behavior portrait engine, and outputting a risk score; 3, dynamic strategy decision making, wherein a decision making engine executes hierarchical control according to the risk score; 4, continuous session monitoring and real-time adjustment are carried out; step 5, when risk upgrading is detected in the session, degrading the session authority, limiting high-risk operation, terminating the session, and retaining evidence obtaining data; step 6, audit event generation and portrait updating; and step 7, strategy optimization closed loop. According to the method, the risk score is calculated in real time based on the AI behavior portrait, transition from static authorization to dynamic permission adjustment is realized, and internal threats such as voucher stealing and the like are effectively blocked.
Owner:JINGDEZHEN SHANJIANG TECHNOLOGY CO LTD

Data security monitoring method based on risk early warning

The invention discloses a data security monitoring method based on risk early warning, particularly relates to the field of data security, and comprises the steps of multi-source data acquisition, index system calculation, comprehensive threat scoring, dynamic risk judgment and response strategy execution. According to the method, a three-dimensional monitoring system is constructed through a multi-source heterogeneous data fusion analysis framework, a traditional single-dimensional monitoring blind area is eliminated, a quantitative score is generated by combining a three-layer nonlinear evaluation model with double-track baseline analysis and dynamic aggregation of basic parameters, double verification of historical rules and real-time fluctuation is achieved, the threat judgment accuracy is remarkably improved, and the threat judgment efficiency is improved. An intelligent mapping system of risk levels and disposal strategies is established, differential response plans are matched through three-level risk division, and a closed-loop feedback channel is synchronously constructed, so that high-risk events are quickly isolated for evidence obtaining, low-risk abnormities are accurately controlled, and a complete iterative loop of assessment disposal optimization is formed. And the active adaptive capacity and the response timeliness of the security defense system are enhanced.
Owner:BEIJING GEER GUOXIN TECH CO LTD

AI protection engine construction method and system based on Web application

The invention relates to the technical field of AI protection, and discloses an AI protection engine construction method and system based on Web application. The method comprises the steps of obtaining a Web application HTTP request and performing semantic analysis to obtain request feature data; performing multi-dimensional threat feature extraction to obtain a Web request threat feature set; performing mode matching on the Web request threat feature set and a preset attack mode library to obtain a threat type judgment result and attack intention information; performing time sequence behavior analysis to obtain a Web behavior abnormal index; comprehensive decision making is carried out through a multi-agent collaborative decision making system, and a defense decision making scheme is obtained; according to the defense decision scheme, a corresponding defense component is selected through a defense execution engine for safety protection, and a Web request processing result is obtained. According to the method, corresponding protection measures can be taken aiming at requests of different risk levels, so that logic vulnerability attacks which are difficult to detect by a traditional system are effectively identified and defended.
Owner:SHAOGUAN COLLEGE

Information security adaptive protection method and system based on artificial intelligence

The invention discloses an information security adaptive protection method and system based on artificial intelligence, and relates to the field of security protection, and the method comprises the steps: dynamically collecting multi-dimensional asset data through distributed nodes, carrying out the edge calculation preprocessing, and extracting features through a deep learning model; carrying out threat identification by fusing LSTM time sequence analysis, an isolated forest and a multi-modal AI detection engine of a knowledge graph; outputting a risk level based on an improved analytic hierarchy process and a fuzzy evaluation model; the AI strategy engine combines the risk level and the business scene to generate an optimal protection strategy, and continuous optimization is carried out through reinforcement learning; a standardized instruction is linked with safety equipment to execute protection, and interception effect closed-loop optimization is fed back in real time; a whole process log is stored through a block chain, and an attack evidence chain is generated through an AI traceability model. The method has the advantages that the information security protection capability is comprehensively improved through hierarchical data acquisition, multi-modal threat detection, scientific situation evaluation, dynamic generation of an optimization protection strategy and combination of block chain evidence storage and AI traceability.
Owner:HEFEI XINGSHENG NETWORK TECH CO LTD

Cybersecurity threat detection and mitigation classification system

In some implementations, a cybersecurity threat detection and mitigation system is provided. The system refines an artificial intelligence (AI) model with a corpus of historical data that represents security events that occurred, queries that were submitted by security analysts in response to the security events, and actions that were performed for mitigating the security events. Telemetry data that corresponds to behavior and performance of a computer network is collected and provided to the AI model. Based on the telemetry data, the AI model predicts a potential security threat to the computer network and performs an assessment of risk to the computer network. When the assessment of risk to the computer network indicates that the potential security threat is an actual security threat, a security alert that corresponds to the actual security threat is triggered. Other embodiments are described and claimed.
Owner:ARCTIC WOLF NETWORKS INC

Network security situation awareness method and system

The invention relates to the technical field of network security, in particular to a network security situation awareness method and system, and the method comprises the following steps: extracting a source IP address and a target IP address based on a network behavior record, carrying out the statistics of the number of used ports, the transmission direction and the time interval value, analyzing the direction change times and the time interval difference, and screening abnormal communication pairs. And generating an abnormal communication pair set. According to the invention, through analyzing port usage, transmission direction and time interval value, deeply mining communication features, screening abnormal communication pairs and improving identification accuracy, dividing a time sequence window, analyzing rate fluctuation and frequency distribution, locking an unstable time window, combining with a multi-dimensional data classification behavior mode, and extracting a switching path and priority, a multi-dimensional data classification behavior mode is combined. Potential threat paths are identified independently, global threat situations are identified through node interaction relation statistics and correlation analysis and an expansion range, threat assessment precision and efficiency are enhanced, and comprehensive and reliable risk protection capability is provided for network managers.
Owner:JIANGSU ZHOUQI DIGITAL TECH CO LTD

Network defense agent system based on large language model

The invention belongs to the field of network security, and particularly discloses a network defense agent system based on a large language model. Through the design of the sensing layer, the decision analysis layer and the action execution layer, comprehensive protection of network threats is realized. The sensing layer is responsible for collecting original information from multiple channels and converting the original information into standardized data; the decision analysis layer performs modeling and threat reasoning on attack behaviors, evaluates a risk level and predicts subsequent actions; and the action execution layer specifically executes defense operation according to the defense strategy scheme output by the decision analysis layer. In addition, the application also constructs a data set oriented to attack and defense confrontation, records a complete attack sequence, defense response and effect evaluation thereof, and provides a reliable basis for continuous learning of defense agents. Experimental results show that the framework provided by the invention is superior to the traditional method in the aspects of attack detection accuracy, attack chain identification and defense strategy generation, and has stronger adaptability and real-time response capability.
Owner:HUAZHONG NORMAL UNIV +1

Multi-source security intelligence collaborative analysis method and system fused with AI intelligent agent

The invention relates to the technical field of network and information security, and discloses a multi-source security information collaborative analysis method and system fused with an AI intelligent agent, and the method comprises the steps: collecting security related data; cleaning and normalizing the collected data, and extracting target security features from the preprocessed data; constructing a plurality of AI agents for different data sources, and generating a preliminary threat judgment result through semantic understanding, behavior pattern recognition and association rule mining based on target security features; performing time sequence fusion on the preliminary threat judgment result, constructing a dynamic security situation model, capturing a threat evolution trend, and dynamically determining a risk level and a priority processing sequence of an event in combination with threat intelligence; according to the risk level and historical response experience, the AI intelligent agent generates an automatic response suggestion and pushes the automatic response suggestion to operation and maintenance personnel; according to the invention, the threat identification capability is improved.
Owner:BEIJING HUAQING XINAN TECH CO LTD

Real-time monitoring and protection method and system for security data of Internet of Things

The invention belongs to the technical field of computers, and particularly relates to an Internet of Things security data real-time monitoring and protection method and system, and the method comprises the steps: collecting equipment communication and state data through an edge agent, and analyzing and extracting standardized metadata; constructing an equipment behavior contour vector based on a sliding window, and dynamically maintaining a global equipment topological graph; triggering a primary alarm in combination with behavior deviation detection and topology abnormity; outputting a threat score and an attack intention through rule matching and Bayesian network double-engine collaborative reasoning; and executing automatic response according to grading, and feeding back and correcting a behavior baseline to realize closed-loop optimization. The system comprises a data acquisition module, a protocol analysis module, a behavior modeling module, a topology maintenance module, an anomaly detection module, a collaborative reasoning module, an automatic response module and a baseline correction module. Through full-link real-time modeling and cross-device collaborative analysis, the attack detection rate is significantly increased to 98% or above, the false alarm rate is lower than 2%, the response delay is controlled within 800 milliseconds, and the security and adaptive ability of the Internet of Things system are enhanced.
Owner:HEBEI XIONGAN WEILI TECHNOLOGY CO LTD