Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

182 results about "Threat assessment" patented technology

Threat Assessment is the practice of determining the credibility and seriousness of a potential threat, as well as the probability that the threat will become a reality. Threat assessment is separate to the more established practice of violence-risk assessment, which attempts to predict an individual's general capacity and tendency to react to situations violently. Instead, threat assessment aims to interrupt people on a pathway to commit "predatory or instrumental violence, the type of behavior associated with targeted attacks," according to J. Reid Meloy, PhD, co-editor of the International Handbook of Threat Assessment. "Predatory and affective violence are largely distinctive modes of violence."

Signaling network vulnerability attack simulation and prevention system based on AI

The invention discloses an AI-based signaling network vulnerability attack simulation and prevention system, which comprises a signaling sensing layer, which is deployed in a core network element to carry out hardware-level decoding of an SS7 / Diameter / SIP / 5G-NR protocol, dynamically extracts protocol field-level metadata through a YARA rule base and generates a standardized signaling log; the threat modeling layer is used for receiving a signaling log output by the signaling sensing layer, generating mixed traffic after injecting a simulation attack, outputting the mixed traffic to the anomaly detection layer, constructing a multi-dimensional feature encoder by using a parameterized quantum gate based on a quantum generative adversarial network and a GFlowNet stream generation engine, generating a compliance attack vector in combination with the constraint of a 3GPP protocol state machine, and outputting the compliance attack vector to the anomaly detection layer; meanwhile, attack trajectory diversity sampling is completed through a Diameter protocol AVP nested state tree and a two-factor award function; the anomaly detection layer is used for receiving the mixed flow of the threat modeling layer and outputting a threat evaluation result to the response processing layer; and the response processing layer is used for receiving the threat assessment result of the anomaly detection layer and issuing a defense instruction to the signaling sensing layer.
Owner:BEIJING TIANYUN XINAN TECH CO LTD

Method and device for identifying forest fire hidden danger of power transmission line based on multi-modal large model

The invention discloses a forest fire hidden danger identification method and device for a power transmission line based on a multi-modal large model, and the method comprises the steps: constructing a forest fire hidden danger identification model for a smog or flame-containing image outputted by a conventional target detection model, and enabling the model to guide a dialogue set through the combination with forest fire hidden danger identification, thereby achieving the recognition of the forest fire hidden danger. The dialogue context and the image visual features are fused, so that the deep fusion of the text semantics and the firework image features is realized; and finally, inputting the deeply fused features into a large language model, so that a forest fire hidden danger output dialogue of the power transmission line can be obtained by utilizing the deep semantic understanding capability of the large language model, and then a forest fire hidden danger recognition result of the power transmission line is obtained. Therefore, according to the invention, the judgment of whether the smoke and fire can damage the power transmission line is realized, the technology upgrade from smoke and fire existence detection to equipment threat research and judgment is completed, and on the basis, the problems of resource waste and untimely crisis response caused by reporting all smoke and fire information in the traditional technology can be avoided.
Owner:STATE GRID SICHUAN ELECTRIC POWER CORP ELECTRIC POWER RES INST

Detecting package execution for threat assessments

Detecting package execution for threat assessments, including: receiving, from an agent on a host of a cloud deployment, data describing one or more active packages installed on the host, wherein each of the one or more active packages are identified by the agent from a plurality of packages in response to detecting a corresponding file open event; and generating a threat assessment for the host describing which of the one or more active packages have any known vulnerabilities.
Owner:FORTINET INC

Unmanned aerial vehicle intrusion real-time alarm and countering guidance system based on RID information

The invention discloses an unmanned aerial vehicle intrusion real-time alarm and countering guidance system based on RID information. The system comprises a multi-source information acquisition and fusion module, an intrusion detection and threat evaluation module, a real-time alarm and countering strategy generation module, a feedback evaluation and strategy iteration module, a signal loss prediction and compensation module, a comprehensive processing terminal module and the like. The system establishes a three-dimensional geofence model by analyzing remote identification information of the unmanned aerial vehicle and fusing radar, photoelectric, electromagnetic and other multi-source data, and performs dynamic judgment and multi-factor threat grading on a target intrusion state. Multi-mode alarm is automatically triggered according to the threat level, and a hierarchical countering scheme from broadcast alarm and electromagnetic interference to physical capture is generated; and when the RID signal is lost, the system realizes continuous tracking and state recovery of the target by using a motion prediction and probability association algorithm.
Owner:BAY AREA LOW ALTITUDE RESEARCH INSTITUTE (GUANGDONG) CO LTD

Anomaly-based mitigation of access request risk

Access to secured items in a computing system is requested instead of being persistent. Access requests may be granted on a just-in-time basis. Anomalous access requests are detected using machine learning models based on historic patterns. Models utilizing conditional probability or collaborative filtering also facilitate the creation of human-understandable explanations of threat assessments. Individual machine learning models are based on historic data of users, peers, cohorts, services, or resources. Models may be weighted, and then aggregated in a subsystem to produce an access request risk score. Scoring principles and conditions utilized in the scoring subsystem may include probabilities, distribution entropies, and data item counts. A feedback loop allows incremental refinement of the subsystem. Anomalous requests that would be automatically approved under a policy may instead face human review, and low threat requests that would have been delayed by human review may instead be approved automatically.
Owner:MICROSOFT TECHNOLOGY LICENSING LLC

Edge device network threat detection method and system based on large electric power model

The invention relates to the technical field of network security, and particularly discloses an edge device network threat detection method and system based on an electric power large model, and the method comprises the steps: capturing a network message sequence in real time, extracting a time sequence randomness feature and a semantic deviation feature from a time dimension and a protocol dimension, and carrying out the fusion to form a comprehensive threat feature vector; performing multi-dimensional feature analysis and time sequence modeling by adopting a lightweight electric power large model to realize millisecond-level threat assessment; establishing a multi-level response mechanism, dynamically triggering a differential protection strategy according to the threat level, and ensuring the reliability and consistency of response actions through digital signature and collaborative verification; according to the method, the complex network attack in the power edge equipment can be effectively identified, the threat detection accuracy and the system defense capability are improved, and the strict requirements of a power system on real-time performance and reliability are met.
Owner:STATE GRID JIANGXI ELECTRIC POWER CO LTD RES INST +1

Dynamic cybersecurity policy management based on contextual adaptive learning

A computerized system for dynamic cybersecurity policy using AI-based contextual adaptive learning includes an AI system that evaluates business contexts, risk tolerance, and productivity impact to generate threat intelligence assessments. The system includes a Contextual Adaptive Learning module that dynamically adjusts cybersecurity policies based on threat assessments to create security workflows. A Cybersecurity Mesh Development module that integrates policies across security frameworks. A Dynamic Scenario Catalog module that updates policy adjustments based on threat intelligence. An Automated Workflow Orchestration module that creates and refines security workflows for optimal efficiency. A Policy Recommendation and Automation module that generates prioritized security recommendations and automates policy changes based on organizational risk profiles and current security controls. This system harmonizes security policies while considering business context, risk, and productivity impacts.
Owner:PURATHEPPARAMBIL SANTHOSH KUNJAPPAN +2

Unmanned aerial vehicle detection method and system capable of sharing aperture

The invention relates to the technical field of unmanned aerial vehicle detection, and discloses a common-aperture unmanned aerial vehicle detection method and system, and the method comprises the steps: obtaining multi-sensor original data and a state data set, and carrying out the standardization; in combination with the state data set, performing state updating and de-noising processing; if data missing or abnormal fluctuation is detected, filling and removing and time sequence storage are carried out, and a historical track sequence is formed; performing feature calculation to obtain a motion feature vector; classifying by using a support vector machine to obtain a target motion mode classification label; if the trajectory is an evasive type or an aggressive type, triggering a high-priority tracking process, and training by using a long-short-term memory network to obtain a predicted trajectory coordinate point set; unifying the coordinates to a global reference framework to obtain a global prediction trajectory, and calculating an intersection point of the global prediction trajectory and a preset no-fly zone to obtain an intersection detection result; generating a real-time alarm signal; and performing comprehensive threat assessment to obtain a threat target detection conclusion. According to the method, the threat assessment accuracy can be improved.
Owner:CCCC REMOTE SENSING TIANYU TECH JIANGSU CO LTD

Computer network security data processing method and system based on artificial intelligence

The invention discloses a computer network security data processing method and system based on artificial intelligence, and the method comprises the steps: building a multi-channel deep learning fusion model, extracting spatial local features in a traffic sequence through employing a 1D-CNN one-dimensional convolutional neural network, capturing a long-range time sequence dependence relation between log events, and carrying out the recognition of the long-range time sequence dependence relation between log events; modeling the user operation behavior sequence based on an LSTM (Long Short-Term Memory) network, and fusing the feature weight by using an attention mechanism to obtain a fused feature vector; inputting the fusion feature vector into a classifier established based on an OS-ELM online sequence extreme learning machine to perform real-time threat assessment, and outputting a probability index of network attacks occurring in a short time in the future; and generating a cooperative defense decision according to the network attack probability index, and sending the cooperative defense decision to security equipment for execution. Excessive defense or insufficient protection is avoided, and the cooperation efficiency of safety equipment is remarkably improved.
Owner:SHANDONG CHRISTIE CULTURAL IND CO LTD

Multi-modal data fusion-based anti-collision early warning method, device, equipment and medium for loader

The invention relates to the technical field of aviation safety, and discloses a multi-modal data fused anti-collision early warning method, device and equipment for a carrier and a medium, and the method comprises the steps: obtaining multi-modal data which comprises radar point cloud data and a photoelectric image; respectively preprocessing the radar point cloud data and the photoelectric image to obtain radar effective point cloud, a semantic mask and confidence; performing cross-modal filtering fusion based on the radar effective point cloud, the semantic mask and the confidence coefficient to obtain a multi-dimensional feature point cloud; and constructing a threat assessment model based on the multi-dimensional feature point cloud, and performing early warning on collision prevention of the carrier based on the threat assessment model. According to the invention, the automatic detection of the threat target in the flight of the aerial carrier is realized, the measurement distance is farther, the measurement precision is higher, and the problems of short anti-collision detection distance and low detection precision in the prior art are solved.
Owner:BEIJING JIAOTONG UNIV +1

Multi-modal target fusion and evaluation method

The invention discloses a multi-modal target fusion and evaluation method, which comprises the steps of performing alignment preprocessing on multi-source observation data to generate multi-source time alignment observation data and multi-source sensor state data; executing single-source target detection and initial threat estimation, and constructing single-source target state data and initial target threat evaluation data; based on the single-source target state data, the initial target threat assessment data and the multi-source sensor state data, executing multi-sensor target track association and fusion by applying threat consistency constraint, and generating multi-sensor fusion target model data; and based on the multi-sensor fusion target model data and the multi-source sensor state data, executing a multi-sensor collaborative scheduling decision by applying threat reduction income evaluation, and determining multi-sensor scheduling scheme data. According to the method, deep coupling of association and scheduling on the threat assessment task is realized, and the association accuracy and the scheduling decision effectiveness are improved.
Owner:NANJING ARTIFICIAL INTELLIGENCE CHIPS RES INST OF AUTOMATION CHINESE ACAD OF SCI

Anti-quantum cryptography migration method and system for power system

The invention relates to the technical field of data security, in particular to a quantum cryptography migration resisting method and system for a power system, and the method comprises the steps: carrying out the quantum threat risk assessment of a communication link based on the layering and partitioning architecture features of the power system; obtaining attribute data of the encryption component, and performing parallel migration risk analysis on the encryption component in combination with a quantum threat risk assessment result to generate an anti-quantum migration risk matrix; carrying out compatibility evaluation on a traditional public key algorithm and an anti-quantum cryptography algorithm based on algorithm features, and constructing a double-track encryption migration strategy; dynamically adjusting a double-track weight ratio, and constructing a double-track encryption hierarchical migration strategy based on a control hierarchy to which a communication link belongs; and executing the double-track encryption layered migration strategy and monitoring the migration effect, and performing self-adaptive correction on the double-track encryption layered migration strategy based on the migration effect. According to the method, a quantum threat assessment and double-track encryption layered migration mechanism is constructed, so that safe and smooth migration of the power system under the threat of quantum computing is realized.
Owner:NANJING NANZI DIGITAL SECURITY TECH CO LTD +1

Digital twin smart park security management system based on artificial intelligence

The invention provides a digital twin smart park security and protection management system based on artificial intelligence, and relates to the field of security and protection management, and the system comprises a multi-mode sensing network which is used for collecting park environment data through a multi-mode sensor network, and carrying out the preprocessing of the data, and obtaining an environment data set; the digital twin modeling module is used for constructing a park three-dimensional virtual model based on the environment data set; the semantic alignment module is used for defining a dynamic security semantic rule based on the three-dimensional virtual model and carrying out semantic alignment of multi-modal features on the environment data set; the threat assessment module is used for performing threat assessment on the aligned semantics based on a knowledge graph and a Bayesian network; and the resource scheduling execution end is used for generating a disposal plan according to the evaluation result and realizing security response through an execution terminal. The method is used for solving the problems of information isolated island, response lag, high false alarm rate, fuzzy situation awareness and the like of a park security system in the prior art.
Owner:XIANGXING TECH ENG (GUANGDONG) CO LTD

Multi-level network threat dynamic identification method based on graph neural network

The invention discloses a multi-level network threat dynamic identification method based on a graph neural network, and the method comprises the following steps: collecting multi-source heterogeneous network security data, and carrying out the preprocessing; constructing a multi-level network threat graph; inputting the multi-level network threat graph into an improved GraphSAGE network to carry out graph embedding modeling; identifying an attack propagation path, and extracting a risk sub-graph region serving as a candidate attack chain; performing threat level evaluation on the risk sub-graph region, and calculating an overall threat score of the risk sub-graph region; and comparing the overall threat score with a preset threshold value, if the overall threat score exceeds the threshold value, determining that the threat is a high-risk threat, and outputting an early warning result. The multi-level threat graph is modeled through the graph neural network, attack chain recognition and threat evaluation are achieved, and the method has the advantages of being high in expressive power, accurate in recognition and fast in response.
Owner:BEIJING HAISHUO INFORMATION TECHNOLOGY CO LTD

Computer augmented threat evaluation

An automated system attempts to characterize code as safe or unsafe. For intermediate code samples not placed with sufficient confidence in either category, human-readable analysis is automatically generated to assist a human reviewer in reaching a final disposition. For example, a random forest over human-interpretable features may be created and used to identify suspicious features in a manner that is understandable to, and actionable by, a human reviewer. Similarly, a k-nearest neighbor algorithm may be used to identify similar samples of known safe and unsafe code based on a model for, e.g., a file path, a URL, an executable, and so forth. Similar code may then be displayed (with other information) to a user for evaluation in a user interface. This comparative information can improve the speed and accuracy of human interventions by providing richer context for human review of potential threats.
Owner:SOPHOS LTD

Unmanned aerial vehicle threat intention prediction method and device and storage medium

The invention relates to an unmanned aerial vehicle threat intention prediction method and device and a storage medium, and is applied to the technical field of anti-unmanned aerial vehicles. The method specifically comprises the steps that through multi-modal deep feature fusion and deep adversarial learning, the system can extract deeper and more abstract unmanned aerial vehicle behavior mode features from multi-source heterogeneous data, so that accurate prediction of the real threat intention of the unmanned aerial vehicle is achieved, the limitation that a traditional method is only based on surface feature judgment is overcome, and the accuracy of the unmanned aerial vehicle threatening intention prediction is improved. The transformation of threat assessment from post-event analysis to pre-event prediction is realized; in the deep adversarial learning framework, various complex unmanned aerial vehicle threat behavior modes including disguise, interference and novel attack strategies can be simulated, and meanwhile, the recognition capability is continuously improved in adversarial training, so that the system can still keep high accuracy and low false alarm rate when facing unknown or variable threats, and the safety of the system is improved. And the robustness and adaptability of the system are obviously enhanced.
Owner:HANGZHOU LANDE INTELLIGENT TECHNOLOGY CO LTD

Video transmission and grading early warning method based on 5G and Wi-Fi hybrid networking

The invention discloses a video transmission and grading early warning method based on 5G and Wi-Fi hybrid networking, and relates to the technical field of network transmission and safety monitoring, and the method comprises the steps: firstly deploying fusion anchor points containing three types of core hardware modules, and determining the number of the fusion anchor points; extracting service time delay and bandwidth demand grades in an XR scene, establishing a QoS parameter mapping relation between 5G and Wi-Fi, and reading key parameters through a fusion anchor point to dynamically allocate bandwidths; based on the parameter matrix and the weight matrix, determining a sampling interval and marking a sampling frame; and finally, evaluating a sampling frame threat parameter and executing hierarchical response. According to the invention, while the collaboration of hybrid networking is improved, the accuracy of threat assessment is improved, and the continuity and security of video transmission in an XR scene are ensured.
Owner:HANGZHOU WUZHI MIXED REALITY TECHNOLOGY CO LTD

Incremental enrichment of threat data

A threat management facility receives data from a variety of sources such as compute instances within an enterprise network, cloud service providers supporting the enterprise network, and third-party data providers such as geolocation services. In order to facilitate prompt notification of potential risks, the threat management facility may incrementally update data for use in threat assessments as the data becomes available from these different sources, and create suitable alerts or notifications whenever the currently accumulated data provides an indication of threat meeting a predetermined threshold.
Owner:SOPHOS LTD

Platform for managing threat data

A platform for managing threat data integrates threat data from a variety of sources including internal threat data from instrumented compute instances associated with an enterprise network and threat data from one or more independent, external resources. Threat assessments are incrementally revised as this threat data is asynchronously received from various sources, and a threat intervention container is automatically created and presented to an investigator when a composite threat score for one or more of the compute instances meets a predetermined threshold.
Owner:SOPHOS LTD

Dynamic threat assessment and control method for non-visual flight of unmanned aerial vehicle in unmanned area

The invention discloses an unmanned area unmanned aerial vehicle non-visual flight dynamic threat assessment management and control method, and belongs to the technical field of air traffic control systems, and the method comprises the steps: obtaining the multi-source sensing data in the flight process of an unmanned aerial vehicle in real time, and generating the state reference parameters of the unmanned aerial vehicle; generating a multi-source quantitative threat data set based on the multi-source sensing data; the state reference parameters of the unmanned aerial vehicle and the multi-source quantitative threat data set are fused to generate a comprehensive flight risk assessment result; generating an adaptive flight management and control strategy based on the comprehensive flight risk assessment result; generating a dynamic adjustment control instruction set based on the adaptive flight control strategy; and performing feedback adjustment based on the execution effect of the dynamic adjustment control instruction set. The technical means of quantifying multi-source threats, carrying out comprehensive risk assessment, generating a self-adaptive control strategy and carrying out feedback optimization based on an execution effect are adopted, so that the autonomous flight safety and intelligent level of the unmanned aerial vehicle in a complex dynamic environment can be remarkably improved.
Owner:BEIJING HUALIAN POWER ENG SUPERVISION CO +2

Low-altitude multi-target TOPSIS threat assessment method based on variable weight VWT-LRA

The invention discloses a low-altitude multi-target TOPSIS threat assessment method based on variable weight VWT-LRA. The method comprises the following steps: 1) selecting five static attributes such as a target type, a damage capability and a protection capability and four dynamic attributes such as a target speed, a target height and a target distance as attribute indexes of an aerial target threat degree assessment system; 2) constructing different membership functions for the dynamic attributes, quantitatively assigning threat degrees of the static attributes, and constructing a target membership matrix; 3) solving a self-adaptive variable weight matrix by adopting a subjective and objective combination weighting method and a variable weight VWT-LRA-based weight adjustment method; and 4) according to the solved target membership degree matrix and the adaptive variable weight matrix, evaluating the target threat degree by using a TOPSIS method based on a relative Euclidean distance, and sorting the target threat degree. According to the invention, the threat degree of the air target can be rapidly and accurately evaluated.
Owner:NANJING UNIV OF SCI & TECH

Low-altitude target detection identification and countering prevention and control system

The invention relates to the technical field of low-altitude prevention and control, in particular to a low-altitude target detection identification and countering prevention and control system which comprises an operation and maintenance management platform, a multi-source data fusion unit, an intelligent noise reduction preprocessing unit, a general command platform, a dynamic threat evaluation unit and a cross-domain collaborative interface module. The detection and recognition precision and efficiency are improved through intelligent noise reduction and multi-source data fusion, intelligent collaborative countering is achieved through an intelligent decision center and a full-link countering unit, global situation awareness is enhanced through cross-domain data collaboration, operation and maintenance management and system stability are optimized by means of a prediction maintenance module and a modular architecture, and the detection and recognition efficiency is improved. The system can make up for the shortages of domestic existing systems, guarantees the airspace safety of key scenes, and reduces the long-term operation cost.
Owner:SHANDONG ZHENGCHEN TECH CO LTD

Unmanned aerial vehicle target identification and threat assessment method and application

PendingCN121167109AData setFeature set
The invention relates to the technical field of unmanned aerial vehicles, and provides an unmanned aerial vehicle target identification and threat assessment method and application, and the method comprises the steps: obtaining an original data stream of an unmanned aerial vehicle target from a multi-source sensor, and carrying out the processing, and obtaining a unified multi-source data set; generating a static feature set by adopting a feature extraction algorithm; generating a dynamic feature set by adopting a time sequence analysis algorithm; performing feature fusion by adopting a neural network model to obtain a fused feature set; generating an unmanned aerial vehicle target knowledge graph by adopting a relation extraction algorithm; extracting association strength from the unmanned aerial vehicle target knowledge graph, and mining threat modes by adopting a graph neural network algorithm to obtain a threat mode set; generating a threat evaluation vector set by adopting a probabilistic reasoning algorithm; generating a countering strategy set by adopting a classification algorithm; and updating the unmanned aerial vehicle target knowledge graph by adopting a feedback learning algorithm to obtain an updated knowledge graph. By adopting the method provided by the invention, the unmanned aerial vehicle target can be quickly and accurately identified, a targeted countering strategy is formulated, and accurate countering is realized.
Owner:AEROSPACE TIMES FEIHONG TECH CO LTD

Low-altitude protection management method and system

The invention relates to a low-altitude protection management method and system, and the method comprises the steps: collecting the real-time flight information and identity information of a low-altitude unmanned plane through a multi-source detection device, and carrying out the identity verification based on the identity information, and obtaining an identity verification result; if the identity verification result is not passed, determining an abnormal target, and countering the abnormal target; if the identity verification result is passed, preprocessing the real-time flight information to generate preprocessed data; performing threat analysis based on the preprocessed data and historical flight data through a machine learning framework to generate a threat level; and determining a new abnormal target according to the threat level, and countering the new abnormal target. The problems of inaccurate identity recognition, lagging threat assessment and extensive countering measures in the prior art are solved, and the low-altitude unmanned aerial vehicle management and control accuracy and real-time performance are improved.
Owner:GENENKOSY INTELLIGENCE SECURITY TECH(HANGZHOU) CO LTD

Unmanned ship path optimization method based on visual detection

The invention discloses an unmanned ship path optimization method based on visual detection, and belongs to the technical field of unmanned ships, and the method comprises the steps: receiving first image information collected by a visual sensor carried by an unmanned ship and navigation parameter information from the unmanned ship, and constructing an environment perception model; performing motion trend prediction and unmanned ship collision risk comprehensive evaluation on the dynamic target; constructing a multi-dimensional threat assessment function, carrying out quantitative sorting on all known collision risk sources, defining a threat assessment index for each risk source, and optimizing a multi-target conflict logic; and dynamically adjusting the course and speed of the unmanned ship based on the output threat assessment result. In the implementation process of the technical scheme, the surrounding environment is perceived in real time through visual detection, parameters such as obstacle types, distances, relative speeds and movement directions are input into a multi-dimensional threat assessment function, and dynamic weighted sorting of different risk sources is realized, so that navigation path optimization is performed on the unmanned ship.
Owner:CHANGZHOU FENGFEI INTELLIGENT CONTROL TECH CO LTD

Topology leakage threat assessment method and device under power grid public data association

The invention relates to a topology leakage threat assessment method and device under power grid public data association, and belongs to the technical field of power grids, and the method comprises the steps: collecting public power data of a power grid, and carrying out the preprocessing and diversified proofreading of the power data, and obtaining a structured time sequence-spatial feature fusion data set; carrying out data set division on the structured time sequence-spatial feature fusion data set according to a time proportion or different generated topological examples to obtain a training set, a verification set and a test set, constructing a total loss function of the link prediction model through an inference relation chain and public data constraints, and obtaining a total loss function of the link prediction model through the training set, the verification set and the test set. And training, verifying and testing the link prediction model by taking the total loss function as a target to obtain a target link prediction model, so that the target link prediction model has the capability of deducing the topology leakage threat, thereby realizing the topology leakage threat assessment on the target power grid and improving the timeliness of the topology leakage threat assessment.
Owner:NATIONAL ENERGY ADMINISTRATION INFORMATION CENTER +1

End confrontation safety system and method based on deterrent defense large model

The invention discloses an end confrontation security system and method based on a deterrent defense large model. The system comprises the deterrent defense large model, an edge deterrent node, a terminal deterrent agent and an adaptive confrontation training framework. The method specifically comprises the following steps: reasoning an attack chain through a deterrent defense large model, deducing a virtual deterrent scene, and generating a countering strategy; and the edge deterrent node extracts the countering strategy and compiles the countering strategy into a terminal executable instruction. And the terminal deterrent agent implements deterrent actions and feeds back deterrent conditions. And continuously optimizing an attack and defense game strategy based on a self-adaptive confrontation training framework. The method supports the dynamic deterrence efficiency, displays the defense strength through the real-time threat assessment and attack countering strategy, reduces the invasion will of an attacker, and enables the attack attempt rate to be reduced. The intelligent confrontation capability is supported, and confrontation sample generation, attack chain reasoning and virtual countering action simulation are realized; and resource collaborative optimization is supported, and the efficiency balance of the center large model and the tail end light-weight model is ensured.
Owner:中国铁路兰州局集团有限公司

Network security situation awareness method and system based on large model and threat assessment

The invention relates to the technical field of network security, in particular to a network security situation awareness method and system based on a large model and threat assessment. The method comprises the following steps: firstly, acquiring and standardizing multi-modal security data in a cloud service environment in real time, distributing a behavior modal cluster for security event metadata through clustering analysis, and generating a security feature vector containing business semantics and behavior dynamic features based on a cluster center relocation technology; then constructing a local situation map reflecting asset topology and an access link by using a cloud security association model; semantic reasoning is performed on the atlas through a large language model, an attack intention is recognized, and an attack path is predicted; and finally, combining the path probability, the asset value and the vulnerability feature to quantitatively calculate a risk index, and automatically generating a response strategy. Semantic compression of massive logs is realized through modal clustering, and the calculation bottleneck of processing original data by a large model is overcome; and in combination with graph correlation and large model reasoning, the crossing from passive warning to active intention prediction is realized.
Owner:BEIJING ZHONGCHUANG HAISHENG TECHNOLOGY CO LTD

ISAC low-altitude safety monitoring system and method based on 5G-A network and security system

The invention relates to a 5G-A network-based ISAC low-altitude safety monitoring system, a 5G-A network-based ISAC low-altitude safety monitoring method and a security and protection system in the field of mobile communication. The ISAC low-altitude safety monitoring system based on the 5G-A network comprises a plurality of 5G-A base stations, edge computing nodes and a general inductance calculation integrated fusion platform. Through software and hardware upgrading of an existing 5G base station, while a communication service is provided, the 5G base station can serve as a distributed and cooperative radar node, and aggregation and preprocessing tasks of data of a plurality of 5G-A base stations are completed at the edge of a network. According to trajectory tracking based on Kalman filtering and intelligent target identification based on a flyer identification AI model, a smooth, continuous and reliable motion trajectory can be output. Therefore, the low-altitude safety monitoring system and the security and protection system can quickly make threat evaluation and give an alarm to the security and protection platform / monitoring terminal, and the technical problem that an existing low-altitude safety monitoring system is complex in information processing flow and low in efficiency is solved.
Owner:安徽明生恒卓科技有限公司

Threat intelligence confidence research and judgment system and method based on multi-source feature fusion

The invention discloses a threat intelligence confidence research and judgment system and method based on multi-source feature fusion. Comprising a multi-source data acquisition module, a data preprocessing module, a feature extension and enhancement module, a feature screening and weight initialization module, an exception and threat preliminary screening module, a feature fusion and association modeling module, an attack scene association and context extension module, a confidence quantitative calculation module and a research and judgment result output and application module. A model verification and feedback module; and a threat information archiving and management module. According to the method, comprehensive acquisition and deep fusion of multi-source heterogeneous data are realized, and the information isolation of a single data source is broken; a multi-dimensional research and judgment result confidence quantitative model is constructed, so that the research and judgment result is more objective and comparable; the feature weight and the association logic can be flexibly adjusted according to different attack scenes, and the accuracy of threat research and judgment under multiple scenes is improved; and through a closed-loop optimization mechanism, the research and judgment precision is ensured to be dynamically improved along with data iteration and scene change.
Owner:北京国御网络安全技术有限公司