Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

740 results about "Threat intelligence" patented technology

Threat intelligence is the analysis of internal and external threats to an organization in a systematic way. The treats that threat intelligence attempts to defend against include zero-day threats, exploits and advanced persistent threats (APTs).

Network security big data state evaluation method based on pattern recognition

The invention relates to the technical field of network security, in particular to a network security big data state evaluation method based on pattern recognition, which comprises the following steps of: extracting multi-modal features from a network flow log, a system event log, a host behavior log and threat intelligence data, generating a feature matrix, performing feature dimensionality reduction by adopting an auto-encoding network, and obtaining a network security big data state evaluation result; carrying out attack behavior classification and abnormal mode identification in combination with unsupervised clustering and a graph neural network; constructing an attack transition probability matrix based on a Markov model; forming a time sequence attack chain; predicting an attack development trend; and a dynamic protection instruction is issued to the safety equipment. According to the method, the unknown attack detection capability can be improved, the time sequence attack traceability is enhanced, the security situation assessment is optimized, and the method is suitable for security situation awareness in cloud computing, industrial internet and large-scale network environments.
Owner:SHANDONG ENERGY GRP CO LTD +1

Network traffic anomaly detection model training method and device and readable storage medium

The invention provides a network traffic anomaly detection model training method and device and a readable storage medium, and the method comprises the steps: extracting a traffic statistical feature vector according to original network traffic data, and generating an initial mixed data set; generating a confrontation disturbance sample output enhanced feature matrix based on the initial mixed data set; constructing a self-adaptive feature fusion rule based on the enhanced feature matrix, embedding asset association degree parameters into an attention calculation layer of a feature encoder, and outputting encoding features fusing threat intelligence; inputting the coding features fused with the threat intelligence into a pre-constructed initial detection model, generating false report and missing report correction labels based on the suspicious traffic fragments, and outputting an adversarial sample correction data set; and performing adversarial training on the initial detection model through the adversarial sample correction data set to obtain an incremental detection model for network traffic anomaly detection. According to the invention, the detection precision, the anti-interference capability and the real-time defense response capability of the detection model to novel attacks can be improved.
Owner:CHINA UNITED NETWORK COMM GRP CO LTD

Network threat multi-modal detection method based on large model

The invention discloses a network threat multi-modal detection method based on a large model, and belongs to the technical field of network security, and the method comprises the steps: collecting three types of heterogeneous data of NetFlow flow of a network layer, a system call chain sequence of a host layer and a protocol load of an application layer, and carrying out the desensitization processing and feature coding to generate a unified tensor format; the method comprises the following steps: through network security threat intelligence and MITRE ATTamp; performing supervision fine tuning on the large model by using a CK attack chain sample, and constructing a network threat identification special model; cross-device behavior characteristics are extracted through a model self-attention mechanism, and a dynamic behavior map is constructed; and finally, comprehensively evaluating an attack mode matching degree, a node vulnerability mean value, historical alarm association and an attack path risk by adopting a weighted fusion algorithm, and triggering a high-confidence alarm when a comprehensive score exceeds 0.8. According to the method, through multi-modal data fusion and dynamic graph analysis, the detection precision and response efficiency of the complex attack chain are improved.
Owner:SOUTHEAST UNIV

Exposure and Attack Surface Management Using a Data Fabric

The disclosed embodiments provide systems and methods for continuous exposure and attack surface management using a data fabric. Data from multiple heterogeneous cybersecurity sources, including vulnerability scanners, threat intelligence, cloud security tools, and endpoint monitoring systems, is ingested and integrated into a semantically harmonized representation, such as a security knowledge graph. This unified data model normalizes, correlates, and contextualizes diverse cybersecurity information, enabling comprehensive and real-time assessment of an organization's cybersecurity risk posture. Automated workflows trigger proactive remediation actions based on dynamically calculated exposure metrics. Additional embodiments leverage the same data fabric architecture to support specialized cybersecurity use cases, including unified vulnerability management (UVM), cyber asset attack surface management (CAASM), continuous threat exposure management (CTEM), and asset exposure management (AEM).
Owner:AVALOR TECH LTD

Network information security protection method and system based on artificial intelligence dynamic defense

The invention relates to a network information security protection method and system based on artificial intelligence dynamic defense. The method comprises the following steps: constructing a multi-level security policy library containing basic defense, scene defense and emergency response based on preprocessed network data features (including protocol features, behavior sequences and abnormal indexes); then, combining real-time threat intelligence and a network environment state, and utilizing a strategy combination optimization algorithm to generate a weight matrix reflecting strategy priorities and dependency relationships; dynamically extracting and fusing various defense strategies from a strategy library according to the weight matrix to form a customized defense scheme; and eliminating resource competition and logic contradiction between strategies through a conflict detection mechanism, and finally deploying a conflict-free optimization scheme to a target node. By adopting the method, collaborative deployment of multi-dimensional security policies can be realized, and the accuracy and real-time performance of security protection in a complex network environment are remarkably improved.
Owner:ZHANGYE ZHICHENG ELECTRONIC TECH CO LTD

Network security intelligent management and control system based on big data

The invention discloses a network security intelligent management and control system based on big data, and relates to the field of network security management. Comprising a data acquisition processing module, an intelligence fusion analysis module, a threat dynamic detection module, an attack deduction prediction module, a virtual mapping simulation module, an edge collaborative defense module, a defense strategy optimization module, an automatic decision execution module and a threat intelligence sharing module. According to the method, the detection capability of complex network attacks is improved, the attack path in the network environment can be visually presented, the security operation and maintenance efficiency is improved, the attack path is accurately blocked, and the attack success rate is reduced; comprehensive security event priority ranking can be realized, the scientificity of defense decision is improved, meanwhile, the system can adapt to different attack scenes, the defense efficiency is improved, it is ensured that a defense strategy always adapts to the current security situation, resource waste is avoided, and the defense cost-benefit ratio is improved.
Owner:JINAN JUBANG INFORMATION TECHNOLOGY CO LTD

APT attack path reconstruction method based on time sequence diagram comparison clustering and medium

The invention discloses an APT attack path reconstruction method based on time sequence diagram comparison clustering and a medium. A security event standardized data set is obtained; mapping each security event into a multi-modal node through a heterogeneous time sequence diagram set construction method, and generating a directed edge to construct and complete a heterogeneous time sequence diagram set; a stage embedding time sequence diagram set is obtained through the joint attack stage set; outputting a time sequence diagram similarity matrix by adopting a multi-scale diagram similarity algorithm of time alignment perception; generating an event semantic sparse matrix based on the threat intelligence knowledge graph; obtaining an image clustering result set; uncertain samples in the graph clustering result set are obtained and processed, and an APT attack path reconstruction result is obtained. The problem that an APT attack path reconstruction method mainly depends on rule matching, single-dimensional feature comparison and manual analysis of security logs or alarm streams is solved, the interpretability of APT traceability is greatly enhanced, and subjective errors of manual research and judgment are reduced.
Owner:EVERSEC BEIJING TECH

High-accuracy threat intelligence assisted network threat tracing method

The invention discloses a high-accuracy threat intelligence assisted network threat tracing method, which comprises the following steps: S1, collecting and preprocessing multi-source network security data, and constructing a time-marked event sequence set; s2, constructing an optimized Transform network model, and processing an attack event sequence by using position coding and time embedding; s3, a black swan optimization algorithm is initialized, and a Transform structure hyper-parameter is dynamically optimized; s4, outputting an attack event semantic vector, and constructing an attack path semantic map; s5, the intelligence information vector is embedded into a Transform hidden space; s6, calculating semantic similarity and dependency intensity, and generating an attack source candidate set and a traceability path; s7, outputting an attack traceability path, a starting point node and an information label, and generating a structured traceability report; and S8, according to the traceability result feedback, updating the black swan algorithm and the Transform model. The method is used for realizing intelligent modeling of multi-source network attack events and high-accuracy traceability analysis of attack source nodes.
Owner:GUANGXI POWER GRID CORP

Network security threat research and judgment method, system and equipment and storage medium

The invention discloses a network security threat research and judgment method, system and device and a storage medium, and the method comprises the following steps: S1, obtaining network traffic, terminal logs, application program interface calling records and threat intelligence data in real time, carrying out the standardized cleaning and format conversion of the data, and building a unified data lake; s2, matching, identifying and determining threats through a preset known threat feature library, constructing a normal behavior baseline by using an unsupervised learning algorithm, and marking suspicious events deviating from the baseline; s3, for the suspicious event marked in the step S2, mining a potential attack path and an attack intention by combining knowledge graph technology associated asset information, a historical attack chain and a homologous IP address; and S4, based on the attack success probability, the influence asset importance and the diffusion speed, calculating a threat level by adopting a fuzzy comprehensive evaluation model, and generating a research and judgment report containing disposal suggestions.
Owner:CRCC DEV GRP CO LTD +1

Network security analysis early warning system based on artificial intelligence

The invention discloses a network security analysis early warning system based on artificial intelligence, and the system comprises a data collection layer which captures full flow based on DPI, aggregates firewall logs, terminal behaviors and threat intelligence, and constructs a structured data pool; through TLS fingerprint identification of AI driving, the encrypted traffic is penetrated, and a sampling strategy is dynamically adjusted in combination with reinforcement learning. The intelligent analysis layer is used for carrying out cross validation on known threats and abnormal behaviors; the time sequence CNN extracts encrypted traffic features, and a novel threat detector is rapidly generated by using historical attack fragments in combination with a meta-learning framework; sHAP value driving dynamic feature selection and optimization feature vector input; the decision-making early warning layer is used for fusing multi-source features through a Bayesian network and generating 0-100 score risk scores; a self-adaptive threshold module is combined to adjust a score threshold in real time, and a high-risk event is pushed; the collaborative response layer is used for triggering a preset decision tree, deploying a GAN dynamic honeypot to trap an attacker and reversely tracing; the Neo4j visually restores the attack path, and blocking is executed after the threat is confirmed by a progressive response mechanism.
Owner:CHINA GEOLOGICAL SURVEY XINING NATURAL RESOURCES COMPREHENSIVE SURVEY CENT

Network attack detection method based on dynamic graph coding

The invention belongs to the technical field of network security, provides a network attack detection method based on dynamic graph coding, and solves the problems of poor dynamic adaptability of an attack path and missing of timing constraint in the prior art. The method comprises the following steps: constructing a dynamic threat map, extracting a triple of heterogeneous threat intelligence by using a RoBERTa model, and adding a timestamp and a confidence attribute; a dynamic graph encoder for time sequence perception is designed, semantic and evolution laws are fused through periodic time coding and a multi-head time sequence attention mechanism, and feature weights are adjusted in combination with a gating residual layer; an event-driven incremental updating strategy is adopted, and node similarity is calculated to achieve local subgraph updating; a time sequence rule base is established, three-dimensional parameter verification attack chain time sequence logic is defined, and abnormity is judged through conflict scores; and finally, integrating a graph updating module, a dynamic coding module and a constraint analysis module to realize multi-source threat feature matching and attack detection. According to the method, the adaptability of attack path evolution is improved through dynamic graph modeling and real-time increment updating.
Owner:UNIV OF ELECTRONICS SCI & TECH OF CHINA

Data security processing method and system based on distributed storage

The invention relates to a data security processing method and system based on distributed storage, and relates to the technical field of computer information processing. The method comprises the following steps: cutting data into encryption fragments with a configurable number by adopting a dynamic fragmentation strategy, and generating a physically isolated dynamic check block in combination with a timestamp to realize tampering prevention; a dynamic threshold value is dynamically calculated based on the data sensitivity index and the node load, and the node is optimized through the reliability score for cooperative decryption; a database table is divided into independent marshalling storage according to main foreign key association, foreign key fields are encrypted by adopting cross keys, and cross-marshalling access needs to meet a multi-key threshold condition; an intelligent threat perception engine is constructed, access logs and threat intelligence are analyzed in real time, and key rotation, fragment replacement and joint defense response mechanisms are dynamically triggered. According to the invention, full life cycle protection of data is realized, and the problems of key leakage risk and cross-table association attack are effectively solved.
Owner:WUHAN ANYU INFORMATION SECURITY TECH CO LTD

Network security situation awareness method and device for multi-source data fusion, equipment and medium

The invention relates to a network security situation awareness method and device for multi-source data fusion, equipment and a medium, and the method comprises the steps: respectively collecting kernel logs and network flow data, and carrying out the standardization processing to generate a communication data set; constructing a dynamic process link map, defining a communication type, frequency and data volume, and updating a topological relation in real time; a sliding time window is adopted to count communication time sequence characteristics, and abnormal signals deviating from normal distribution are screened in combination with a time sequence analysis technology; training a robustness classifier model through an adversarial sample enhancement technology, fusing a graph neural network to analyze a dependency relationship between processes, and filtering a false alarm signal; and the hidden channel is accurately identified and alarm information is generated in combination with a dynamic similarity threshold and a threat intelligence gain coefficient, so that the problems of insufficient multi-source data fusion, high false alarm rate of a static rule base, failure in detection of weak signals of the hidden channel and the like in a traditional method are solved. And the real-time perception and response capability of APT attacks in a complex network environment is improved.
Owner:MINXI VOCATIONAL & TECHN COLLEGE

Knowledge graph construction and attack path prediction method for network security

The invention belongs to the technical field of network security, and particularly discloses a network security knowledge graph construction and attack path prediction method, which comprises the following steps: acquiring an attack mode of network threat intelligence; constructing a network security knowledge graph based on the security vulnerability and attack pattern classification standard data and the attack pattern of the network threat intelligence; according to the method, an entity relationship in a network security knowledge graph is predicted based on a graph attention network GAT of text enhancement, an attack path is constructed based on the predicted entity relationship, and text enhancement is to introduce text information corresponding to entity nodes into a multi-head attention mechanism layer of the GAT. According to the method, the network security knowledge graph is constructed and the entity relationships are predicted based on the GAT, so that the entity relationships can be quickly integrated, the attack paths are constructed, the paths reveal security holes and attack modes which may be utilized by attackers, and accurate and efficient attack path prediction can be realized.
Owner:HUAZHONG NORMAL UNIV

Threat intelligence dialogue system for interfacing with a proprietary threat intelligence database

An LLM is adapted to generate database queries that are compatible with a proprietary database of a security provider. Adapting the LLM includes evaluating performance of the LLM after initial prompt engineering / fine-tuning to ensure that generated database queries are valid (i.e., comport to the database schema and can be executed to return results). When the LLM performance is satisfactory, a dialogue system uses the LLM to generate database queries from user queries. The dialogue system determines intent of each user query, which informs whether the query is supported. Supported user queries are converted to database queries using the LLM and submitted to the database. The dialogue system leverages another language model to generate a summarized, natural language representation of the database query results and constructs a response from the summary. The dialogue system also checks for XSS and prompt injection before database queries are ultimately submitted to the database.
Owner:PALO ALTO NETWORKS INC

Dynamic security risk assessment and intelligent response system and method based on AI

The invention provides a dynamic security risk assessment and intelligent response system and method based on AI, relates to the field of dynamic security risk assessment and intelligent response, and improves the accuracy and response speed of security protection. The method comprises the following steps: firstly, collecting multi-dimensional security data, carrying out data preprocessing by utilizing an AI technology, and outputting a structured security data stream; then analyzing the data flow based on an AI model, identifying cross-dimension attack features, generating real-time threat intelligence, updating a risk judgment threshold value, generating a security assessment report, automatically generating and executing hierarchical response measures according to the assessment report, feeding back a response execution effect, performing dynamic adjustment, and generating a new security assessment report; and finally, automatically selecting a data transmission mode and rate according to the new security assessment report, and adjusting the acquisition frequency of the sensor. According to the method, through dynamic optimization and an intelligent response mechanism, the recognition and defense capability on complex attacks is remarkably improved.
Owner:CCCC SOUTH CHINA SURVEY & MAPPING TECH CO LTD +1

Information security assessment method and system based on cloud computing

The invention discloses an information security assessment method and system based on cloud computing, and relates to the technical field of information security, and the method comprises the steps: collecting multi-modal data, and carrying out the encryption through employing a node identifier, and generating a spatio-temporal data package; the method comprises the following steps: aggregating threat features by utilizing secure multi-party calculation through edge nodes, constructing a 58-dimensional square matrix, constructing a risk assessment model based on a quantum heuristic algorithm, positioning root cause threats by applying a Do-Calculus algorithm, dynamically adjusting and optimizing model weights by federal reinforcement learning, and outputting threat vectors to a cloud causal engine; the method comprises the following steps: constructing a space-time causal diagram by combining threat intelligence, positioning root cause threats by applying a Do-Calculus algorithm, generating a dynamic defense strategy, optimizing access control by KL divergence constraint, locally encrypting and storing a strategy execution log, and generating an evaluation audit log. According to the method, the problems of insufficient cloud computing multi-modal data relevance, defense lagging and verification fault are solved, and collaborative crossing of evaluation precision and response efficiency is realized.
Owner:ZHENGZHOU FEILONG COMPUTER TECH CO LTD

Multi-modal data fusion network attack detection method

The invention discloses a multi-modal data fusion network attack detection method, and relates to the technical field of computer network security, and the method comprises the following steps: 1, network flow data collection and attribute analysis; step 2, multi-dimensional feature extraction and attack path drawing; 3, cross-modal data fusion and model construction integration are carried out; 4, model activation enabling and attack route evaluation; and 5, real-time data access and attack detection judgment. According to the multi-modal data fusion network attack detection method, through detailed analysis of multi-dimensional attributes of network flow data, potential feature information in the data is comprehensively mined, and multi-source information such as an attack path diagram, terminal equipment log data and threat intelligence data is further fused; and cross-modal interactive learning is carried out to construct a multi-modal attack detection model, so that the limitation of traditional single data source detection is broken through, and the relevance and complementarity among data are fully utilized.
Owner:SUZHOU ZHUOMING INTELLIGENT TECHNOLOGY CO LTD

Network security protection method and system based on block chain

The invention relates to a network security protection method and system based on a block chain, and aims to solve a series of challenges of identity authentication single-point failure, insufficient static block chain fragmentation, threat detection limitation, encryption algorithm security problem and the like in the existing network security protection technology. According to the method, an on-chain digital identity is generated by fusing an equipment unique identifier and user biological characteristics, dynamic authority management is performed based on the identity, network traffic is detected in real time by using a deep learning model of adversarial training, a threat detection result is generated, an authority level is updated according to the detection result through an intelligent contract, and meanwhile, the user experience is improved. A fragmented block chain network technology is adopted, the number of sub-chains is dynamically adjusted according to a network load, cross-chain threat intelligence synchronization is realized through a relay chain, in addition, a threshold signature and zero-knowledge proof technology is also adopted, permission change records and cross-chain data are encrypted and verified, the security and privacy of the data are ensured, and the security and privacy of the data are improved. According to the invention, the efficiency and reliability of network security protection can be effectively improved, and a safer and more reliable network environment is provided for users.
Owner:BIT MOTION TECHNOLOGY (SHENZHEN) CO LTD

Network security threat information early warning method and system based on big data

The invention belongs to the technical field of network security early warning, and discloses a network security threat information early warning method and system based on big data, and the method comprises the steps: collecting and integrating internal data and external data related to network security based on the big data, carrying out the natural language processing and analysis of unstructured threat information, and constructing a threat entity association relationship through a knowledge graph; constructing an adaptive threat model based on network security threat information of big data and deep learning, and using a convolutional neural network CNN to identify an abnormal mode in encrypted traffic; establishing a user-device behavior baseline through a long short-term memory (LSTM) network; predicting a threat diffusion path in combination with a graph neural network GNN, developing a threat risk quantitative model, and calculating an information risk value by comprehensively considering an attack success rate, an asset value, an influence range value and a response delay; and performing risk prediction on the network security threat information based on the calculated information risk value in combination with calculation and analysis of the information risk attenuation factor.
Owner:江西软件职业技术大学

Intelligent network attack surface prediction method and system based on deep learning

The invention relates to an intelligent network attack surface prediction method and system based on deep learning, and belongs to the technical field of network security and information, and the method comprises the steps: obtaining network asset information, vulnerability distribution information and external threat intelligence data in a target network environment, and carrying out the preprocessing to generate a standardized data set; inputting the standardized data set into a pre-trained deep learning model to extract a feature vector related to the network attack; reasoning and analyzing a potential attack link based on the feature vector and the knowledge graph, and combining an association relationship among a network asset node, a vulnerability node and a threat intelligence node in the knowledge graph; and finally, according to a reasoning analysis result, evaluating an intrusion path possibly utilized by an attacker, outputting an attack surface prediction result, and presenting the attack surface prediction result in the form of an attack path list. According to the scheme, a potential attack link can be subjected to deep reasoning analysis, an intrusion path possibly utilized by an attacker can be accurately predicted, and the effectiveness of network security protection is improved.
Owner:BEIJING HUAYUNAN INFORMATION TECH CO LTD

Network information security adaptive threat intelligence analysis and response method and system

The invention provides a network information security adaptive threat intelligence analysis and response method and system. The method comprises the following steps: acquiring an encrypted traffic load byte stream, and segmenting the encrypted traffic load byte stream into a time sequence traffic matrix according to a time window; and analyzing the communication metadata, matching the features of the threat intelligence library, and generating a dynamic threat fingerprint based on protocol compliance and behavior abnormality. And performing multi-stage wavelet packet decomposition on the matrix, extracting the energy spectrum density, the information entropy and the time-frequency variable coefficient of the high-frequency component, and performing weighted fusion to generate a frequency-domain composite abnormal index representing heartbeat signal characteristics. And identifying hidden heartbeat periodicity and protocol violation modes through a multi-mode fusion mechanism in combination with the frequency domain index and the threat fingerprint, and outputting a threat score. And if the attack exceeds the threshold value, intercepting the flow, verifying a new attack feature, and then reversely updating the threat intelligence library to form a defense self-evolution closed loop. According to the method, automatic interception and closed-loop updating of the threat intelligence library are realized, and the defense adaptability is remarkably improved.
Owner:HANGZHOU GUANGMAI TECH

Automatic operation and maintenance method and system based on artificial intelligence

The invention relates to the technical field of network operation and maintenance, in particular to an automatic operation and maintenance method and system based on artificial intelligence, and the method comprises the steps: collecting detailed log information containing a security event in real time through a security information and event management system configured at a target endpoint; performing cleaning, labeling and structured processing on the log data by utilizing a proxy artificial intelligence system to generate standardized metadata, and performing MITRE ATTamp with the standardized metadata; mapping the CK knowledge base, identifying technical features and behavior patterns of attacks, comparing enriched log data with an external threat intelligence source, analyzing TTP of a known attack group, generating a threat intelligence association report, generating a targeted response plan by using a large language model, generating an executable command sequence according to the response plan, and generating a threat intelligence association report; the proxy executor is connected with the server through a WebSocket protocol, executes a command in a POSIX shell environment, captures and returns an execution result, verifies the execution result, carries out necessary command optimization, records an optimized response to a vector database, and automatically matches a historical event and triggers a predefined response process through a vector retrieval mechanism. And continuous threat monitoring and adaptive response are realized. According to the method, the problem that a closed loop aiming at a terminal executor, data enrichment and historical event recall cannot be formed by security operation and maintenance in the prior art can be solved.
Owner:GUANGZHOU ELECTRIC POWER COMM NETWORK LTD

Infrastructure safety analysis method and system based on large model

The invention provides an infrastructure security analysis method and system based on a large model, and the method comprises the following steps: collecting multi-source heterogeneous data of an infrastructure, including physical equipment sensor data, network flow data, operating system logs and external threat intelligence; converting the multi-source data into standardized feature vectors of a unified time axis through a space-time alignment module; and inputting the standardized feature vector into the fine-tuned large language model for semantic understanding, and generating an equipment behavior semantic description and threat intention analysis result. According to the method provided by the invention, a large language model and reinforcement learning collaborative architecture is provided, and the large language model is improved, so that end-to-end mapping from multi-source data to threat semantics is realized, and the attack detection rate is improved.
Owner:GOLDEN SHIELD TESTING TECH CO LTD

Network security risk assessment method for unmanned aerial vehicle system

According to the network security risk assessment method for the unmanned aerial vehicle system, real-time analysis of an AI algorithm is adopted, dynamic assessment and an automatic defense strategy are combined, real-time monitoring and dynamic adjustment of a risk assessment result can be carried out, it is ensured that effective risk assessment is carried out in a rapidly changing threat environment in the flight process of an unmanned aerial vehicle, and the risk assessment efficiency is improved. The use requirements are met; comprising the following steps: scanning source codes of safety key components of an unmanned aerial vehicle system by adopting a static code analysis tool, and identifying all potential attack points; the system state, network data and sensor information of the unmanned aerial vehicle are collected, threat intelligence is obtained, an AI algorithm is adopted to analyze data in real time, and abnormal behaviors are identified; quantifying the security threat of the current abnormal behavior, and evaluating the attack possibility and potential influence; dynamically adjusting a defense strategy according to a risk assessment result; all security events and response conditions are recorded, attack traceability analysis is formed, the AI model is updated regularly, and the recognition capability of novel attacks is enhanced.
Owner:AKSU POWER SUPPLY COMPANY STATE GRID XINJIANG ELECTRIC POWER

Generative confrontation-driven intelligent security defense method and system

The invention provides a generative adversarial-driven intelligent security defense method and system, and solves the problem of dynamic network security defense through three-layer architecture innovation: 1, data fusion layer reconstruction: employing a multi-modal feature extraction engine driven by an MoE architecture, dynamically allocating computing power resources to a plurality of expert models, and improving the heterogeneous data distillation efficiency; an LLM for fine adjustment in the security field is introduced, a cross-modal semantic similarity matrix is constructed, and the accuracy of unstructured threat intelligence analysis is improved; a second dynamic attack and defense layer is constructed, a GPT-4 architecture attack generator is deployed, and generation of a multi-stage APT attack chain is simulated; a double-agent reinforcement learning framework is designed, and the confrontation training efficiency is improved; upgrading a three-cognitive decision-making layer, constructing a dynamic threat map based on a time sequence diagram neural network, and updating an adjacent matrix in real time; a plurality of agent clusters are deployed, the capabilities of encrypted traffic analysis and attack blocking are improved, and the problems of data layer defects, attack and defense confrontation limitation and decision-making layer bottleneck in the prior art are solved.
Owner:北京国瑞数智技术有限公司

End-network cooperative attack defense method driven by multi-source intelligence

The invention discloses a multi-source intelligence-driven end-network cooperative attack defense method, which comprises the following steps of: S1, respectively acquiring terminal log data, network flow data, threat intelligence data and equipment state data, and carrying out standardization processing on the terminal log data, the network flow data, the threat intelligence data and the equipment state data; s2, constructing a feature data hypergraph by taking the standardized data as nodes; s3, inputting the hypergraph into a depth hypergraph anomaly detection model, extracting high-order correlation features and detecting an anomaly mode; s4, inputting an anomaly detection result into a hypergraph Transform sequence modeling mechanism, performing multi-head attention calculation and dynamic interaction, and generating a dynamic fusion feature; s5, judging an attack behavior in real time according to the dynamic fusion features, and generating an end-network cooperative linkage defense strategy; and S6, issuing a defense instruction in real time according to the defense strategy, and executing end-network cooperative attack defense. According to the invention, the real-time performance and accuracy of end-network cooperative attack defense are improved, and the overall efficiency of network security defense is enhanced.
Owner:GUANGXI POWER GRID CORP

Threat intelligence knowledge graph reasoning method based on improved GNN and reinforcement learning

The invention provides a threat intelligence knowledge graph reasoning method based on improved GNN and reinforcement learning, and the method comprises the steps: constructing a self-encoder based on an improved GNN through introducing a variational mechanism, and carrying out the feature extraction of an original threat intelligence knowledge graph, and obtaining the node information et of a current moment; constructing a strategy network; a reinforcement learning soft reward module calculates a reward r according to the historical path quality of agent migration, and feeds back the reward r to the strategy network; based on the current state, the action, the reward and the new state, updating parameters of the policy network through a policy gradient method; completing the construction of a knowledge reasoning model based on improved GNN and reinforcement learning; obtaining a reasoning result through a built knowledge reasoning model based on improved GNN and reinforcement learning; according to the method, features can be efficiently extracted, rich semantic information can be captured, more accurate representation and reasoning results can be provided, the interpretability of the model is improved, and the reasoning ability can be improved.
Owner:NANJING UNIV OF POSTS & TELECOMM

Cloud environment active defense system based on dynamic honey points

The invention provides a cloud environment active defense system based on dynamic honey spots. The system comprises a honey spot deployment and management module which generates and deploys honey spots, manages honey spot layout and provides honey spot information; the dynamic defense control module monitors network flow, perceives an attack path, analyzes attack behavior characteristics, adjusts honey point layout, generates an adjustment instruction and generates alarm information according to the attack behavior characteristics; the attack chain tracking and analyzing module is used for acquiring attack event data for attack behavior tracking, constructing an attack graph for attack path analysis and attack intention prediction and generating a threat intelligence report; and the system integration and management module monitors the running state and the resource use condition of each module, dynamically distributes system computing resources, and sets an interaction unit to provide interaction. According to the system, a complete deception defense mechanism is constructed, a deception environment is constructed by utilizing honey points, the honey points are dynamically adjusted according to attacks, and quick response and accurate countering are ensured through a flexible defense strategy and multi-layer cooperation.
Owner:GUANGZHOU UNIVERSITY +1

Network attack research and judgment method and system, program product, equipment and medium

The embodiment of the invention provides a network attack research and judgment method and system, a program product, equipment and a medium, the system deploys a plurality of agents, and the method comprises the following steps: inputting an attack sample into an attack feature extraction agent, and constructing an attack feature library based on the extracted attack features; inputting the network security log into a field extraction agent to obtain an extracted attack related field; inputting the attack feature library and the attack related fields into an attack analysis module, and obtaining attack analysis data of the attack analysis module on the attack related fields based on the attack feature library; inputting the threat intelligence data, the asset data and the attack analysis data into a comprehensive analysis report agent to obtain an analysis report including an attack result, an attack severity degree, an influence range and an attack technology; and inputting the analysis report into an attack processing module to obtain an attack processing plan. Attack research and judgment process automation is realized by utilizing the intelligent agent, the analysis, research and judgment capability on known attacks can be improved, unknown attack behaviors can be identified, and closed-loop protection measures are formed.
Owner:BEIJING TOPSEC NETWORK SECURITY TECH +2