Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

557 results about "Threat intelligence" patented technology

Threat intelligence is the analysis of internal and external threats to an organization in a systematic way. The treats that threat intelligence attempts to defend against include zero-day threats, exploits and advanced persistent threats (APTs).

Network security threat research and judgment method, system and equipment and storage medium

The invention discloses a network security threat research and judgment method, system and device and a storage medium, and the method comprises the following steps: S1, obtaining network traffic, terminal logs, application program interface calling records and threat intelligence data in real time, carrying out the standardized cleaning and format conversion of the data, and building a unified data lake; s2, matching, identifying and determining threats through a preset known threat feature library, constructing a normal behavior baseline by using an unsupervised learning algorithm, and marking suspicious events deviating from the baseline; s3, for the suspicious event marked in the step S2, mining a potential attack path and an attack intention by combining knowledge graph technology associated asset information, a historical attack chain and a homologous IP address; and S4, based on the attack success probability, the influence asset importance and the diffusion speed, calculating a threat level by adopting a fuzzy comprehensive evaluation model, and generating a research and judgment report containing disposal suggestions.
Owner:CRCC DEV GRP CO LTD +1

Network security analysis early warning system based on artificial intelligence

The invention discloses a network security analysis early warning system based on artificial intelligence, and the system comprises a data collection layer which captures full flow based on DPI, aggregates firewall logs, terminal behaviors and threat intelligence, and constructs a structured data pool; through TLS fingerprint identification of AI driving, the encrypted traffic is penetrated, and a sampling strategy is dynamically adjusted in combination with reinforcement learning. The intelligent analysis layer is used for carrying out cross validation on known threats and abnormal behaviors; the time sequence CNN extracts encrypted traffic features, and a novel threat detector is rapidly generated by using historical attack fragments in combination with a meta-learning framework; sHAP value driving dynamic feature selection and optimization feature vector input; the decision-making early warning layer is used for fusing multi-source features through a Bayesian network and generating 0-100 score risk scores; a self-adaptive threshold module is combined to adjust a score threshold in real time, and a high-risk event is pushed; the collaborative response layer is used for triggering a preset decision tree, deploying a GAN dynamic honeypot to trap an attacker and reversely tracing; the Neo4j visually restores the attack path, and blocking is executed after the threat is confirmed by a progressive response mechanism.
Owner:CHINA GEOLOGICAL SURVEY XINING NATURAL RESOURCES COMPREHENSIVE SURVEY CENT

Data security processing method and system based on distributed storage

The invention relates to a data security processing method and system based on distributed storage, and relates to the technical field of computer information processing. The method comprises the following steps: cutting data into encryption fragments with a configurable number by adopting a dynamic fragmentation strategy, and generating a physically isolated dynamic check block in combination with a timestamp to realize tampering prevention; a dynamic threshold value is dynamically calculated based on the data sensitivity index and the node load, and the node is optimized through the reliability score for cooperative decryption; a database table is divided into independent marshalling storage according to main foreign key association, foreign key fields are encrypted by adopting cross keys, and cross-marshalling access needs to meet a multi-key threshold condition; an intelligent threat perception engine is constructed, access logs and threat intelligence are analyzed in real time, and key rotation, fragment replacement and joint defense response mechanisms are dynamically triggered. According to the invention, full life cycle protection of data is realized, and the problems of key leakage risk and cross-table association attack are effectively solved.
Owner:WUHAN ANYU INFORMATION SECURITY TECH CO LTD

Intelligent network attack surface prediction method and system based on deep learning

The invention relates to an intelligent network attack surface prediction method and system based on deep learning, and belongs to the technical field of network security and information, and the method comprises the steps: obtaining network asset information, vulnerability distribution information and external threat intelligence data in a target network environment, and carrying out the preprocessing to generate a standardized data set; inputting the standardized data set into a pre-trained deep learning model to extract a feature vector related to the network attack; reasoning and analyzing a potential attack link based on the feature vector and the knowledge graph, and combining an association relationship among a network asset node, a vulnerability node and a threat intelligence node in the knowledge graph; and finally, according to a reasoning analysis result, evaluating an intrusion path possibly utilized by an attacker, outputting an attack surface prediction result, and presenting the attack surface prediction result in the form of an attack path list. According to the scheme, a potential attack link can be subjected to deep reasoning analysis, an intrusion path possibly utilized by an attacker can be accurately predicted, and the effectiveness of network security protection is improved.
Owner:BEIJING HUAYUNAN INFORMATION TECH CO LTD

Automatic operation and maintenance method and system based on artificial intelligence

The invention relates to the technical field of network operation and maintenance, in particular to an automatic operation and maintenance method and system based on artificial intelligence, and the method comprises the steps: collecting detailed log information containing a security event in real time through a security information and event management system configured at a target endpoint; performing cleaning, labeling and structured processing on the log data by utilizing a proxy artificial intelligence system to generate standardized metadata, and performing MITRE ATTamp with the standardized metadata; mapping the CK knowledge base, identifying technical features and behavior patterns of attacks, comparing enriched log data with an external threat intelligence source, analyzing TTP of a known attack group, generating a threat intelligence association report, generating a targeted response plan by using a large language model, generating an executable command sequence according to the response plan, and generating a threat intelligence association report; the proxy executor is connected with the server through a WebSocket protocol, executes a command in a POSIX shell environment, captures and returns an execution result, verifies the execution result, carries out necessary command optimization, records an optimized response to a vector database, and automatically matches a historical event and triggers a predefined response process through a vector retrieval mechanism. And continuous threat monitoring and adaptive response are realized. According to the method, the problem that a closed loop aiming at a terminal executor, data enrichment and historical event recall cannot be formed by security operation and maintenance in the prior art can be solved.
Owner:GUANGZHOU ELECTRIC POWER COMM NETWORK LTD

Infrastructure safety analysis method and system based on large model

The invention provides an infrastructure security analysis method and system based on a large model, and the method comprises the following steps: collecting multi-source heterogeneous data of an infrastructure, including physical equipment sensor data, network flow data, operating system logs and external threat intelligence; converting the multi-source data into standardized feature vectors of a unified time axis through a space-time alignment module; and inputting the standardized feature vector into the fine-tuned large language model for semantic understanding, and generating an equipment behavior semantic description and threat intention analysis result. According to the method provided by the invention, a large language model and reinforcement learning collaborative architecture is provided, and the large language model is improved, so that end-to-end mapping from multi-source data to threat semantics is realized, and the attack detection rate is improved.
Owner:GOLDEN SHIELD TESTING TECH CO LTD

Cloud environment active defense system based on dynamic honey points

The invention provides a cloud environment active defense system based on dynamic honey spots. The system comprises a honey spot deployment and management module which generates and deploys honey spots, manages honey spot layout and provides honey spot information; the dynamic defense control module monitors network flow, perceives an attack path, analyzes attack behavior characteristics, adjusts honey point layout, generates an adjustment instruction and generates alarm information according to the attack behavior characteristics; the attack chain tracking and analyzing module is used for acquiring attack event data for attack behavior tracking, constructing an attack graph for attack path analysis and attack intention prediction and generating a threat intelligence report; and the system integration and management module monitors the running state and the resource use condition of each module, dynamically distributes system computing resources, and sets an interaction unit to provide interaction. According to the system, a complete deception defense mechanism is constructed, a deception environment is constructed by utilizing honey points, the honey points are dynamically adjusted according to attacks, and quick response and accurate countering are ensured through a flexible defense strategy and multi-layer cooperation.
Owner:GUANGZHOU UNIVERSITY +1

Internet of vehicles vulnerability management method, system and device based on block chain, and medium

The invention provides an Internet of Vehicles vulnerability management method, system, device and medium based on a block chain, and relates to the technical field of vehicle networks, the method can comprehensively identify potential safety risks of vehicles through a dynamic and static combined vulnerability detection mechanism, and generates a structured vulnerability report; hash abstract chaining evidence storage is performed on key data of reports and subsequent repair links by using a block chain, so that the whole process of vulnerability discovery, analysis and repair is ensured not to be tampered and traceable, and the authenticity and credibility of data are improved; the integrity of the report is verified at the cloud end, and an AI analysis engine is combined to associate a CVE database and threat intelligence, so that intelligent generation and decision support of a repair scheme are realized; the hash abstract on the chain of the OTA patch is verified at the vehicle end, so that the credibility of the patch source and the integrity of the content are guaranteed; and finally, through feedback of an installation result and secondary uplink archiving, complete closed-loop management from vulnerability discovery to repair verification is formed.
Owner:FIFTH ELECTRONICS RSCH INST OF MINISTRY OF IND & INFO TECH

Intelligent data security exposure surface risk assessment method, system, equipment and medium

The invention provides an intelligent data security exposed surface risk assessment method, system and device and a medium, and relates to the technical field of information security, and the method comprises the steps: constructing an exposed surface asset map through an asset fingerprint recognition engine, and calculating an asset exposure index; constructing a vulnerability knowledge base, and identifying potential vulnerabilities; based on the standard vulnerability score, the vulnerability utilization tool activeness and the attack event frequency in the set time period, calculating the triggering probability of the potential vulnerability as a dynamic vulnerability score; malicious IP access frequency and leakage record matching degree are obtained through firewall logs and dark web monitoring data, and threat intelligence factors are obtained through calculation; calculating an exposed surface risk value in combination with the asset exposure index, the dynamic vulnerability score and the threat intelligence factor; and based on a time decay model, according to the exposed surface risk value and the business influence factor, calculating a residual risk value, and obtaining an exposed surface risk assessment result. The accuracy of risk assessment is further improved through multi-dimensional data fusion.
Owner:YUANBAO TECH

Active defense system and method based on multi-protocol dynamic simulation and distributed trapping

The invention provides an active defense system and method based on multi-protocol dynamic simulation and distributed trapping. The active defense method based on multi-protocol dynamic simulation and distributed trapping comprises the following sub-steps: S1, constructing a multi-protocol dynamic simulation environment; s2, deploying distributed trapping nodes; s3, deep trapping of attack behaviors; s4, attack chain reconstruction and behavior analysis; s5, performing adaptive confusion and adversarial enhancement; s6, automatic threat intelligence production and feedback; by loading the protocol template library and initializing the state machine, the response can be dynamically generated according to the real-time session context, and dynamic simulation of various service protocols is adopted, so that the detection capability on network attacks is improved, potential threats can be captured more quickly, and the risks of missing report and false report are reduced; and through an automatic threat intelligence generation and feedback mechanism, in combination with IOC index identification, structured output and real-time response, a defense strategy can be quickly responded and adjusted.
Owner:CHINA LIFE INSURANCE CO LTD

Network security situation real-time perception and visual display system

The invention belongs to the technical field of network security, and discloses a network security situation real-time perception and visual display system, which comprises the following modules: a real-time data acquisition module, an intelligent analysis and situation evaluation module, a three-dimensional visual display module and an automatic decision processing module. According to the system, dual mechanisms of unsupervised anomaly detection and a supervised machine learning model are fused through an intelligent analysis and situation evaluation module, the recognition precision of unknown anomaly and known threats is improved, and warning, abnormal traffic and asset vulnerability are deeply correlated by using a time sequence event correlation analysis technology; according to the method and the system, the real-time and accurate global situation portrait is formed, meanwhile, a multi-dimensional safety index quantification system is constructed by means of a situation evaluation unit, and a scientific basis is provided for risk hotspot identification and early warning in combination with threat intelligence, asset vulnerability, service criticality and topology dynamic calculation.
Owner:李师谦

Multi-source threat intelligence privacy fusion processing method and system

The invention discloses a multi-source threat intelligence privacy fusion processing method and system, and relates to the technical field of network security threat intelligence analysis and processing, and the method comprises the steps: collecting threat intelligence, and carrying out the cleaning, standardization and desensitization; establishing a threat index semantic model and aligning cross-modal features; the central coordination module completes model aggregation after organization node local training; and based on the aggregation model fusion intelligence, semantic association and attack link reconstruction are established, and a result is generated and fed back for optimization. The technical problems that in cross-organization fusion processing of multi-source heterogeneous threat intelligence, data formats are not uniform, and privacy protection and intelligence collaborative analysis contradictions exist, so that threat detection is not comprehensive and inaccurate, and accurate evaluation and effective management and control requirements are difficult to meet are solved. The technical effects that the multi-source heterogeneous threat intelligence is effectively fused on the premise of privacy protection, the comprehensiveness and accuracy of threat detection are improved, and the requirements for accurate assessment and effective management and control of threats in a cross-organization scene are met are achieved.
Owner:CHINA SOUTHERN POWER GRID COMPANY

Network traffic anomaly real-time detection method based on deep learning

The invention relates to the technical field of network flow detection, in particular to a real-time network flow anomaly detection method based on deep learning, and the system comprises the following steps: S1, carrying out the real-time collection and preprocessing of multi-modal data; s2, performing dynamic feature engineering and sliding window statistics; s3, carrying out online adaptive threshold initialization; s4, multi-modal deep learning model reasoning is carried out; s5, updating the adaptive threshold in real time; s6, abnormal decision making and confidence coefficient calibration; s7, generating interpretability analysis; and S8, performing real-time feedback and online learning. According to the scheme, the capability of detecting hidden and complex attacks is remarkably improved through multi-modal data fusion and dynamic feature engineering, network traffic, system logs, user behavior data and external threat intelligence are synchronously collected, and traffic statistical features, time sequence change features, frequency domain features and distribution features are extracted in real time by using a sliding window mechanism.
Owner:WUXI YUANSHUCHENG TECHNOLOGY CO LTD

Network threat knowledge automatic extraction method, electronic equipment and storage medium

PendingCN120930756AWeb data indexingSemantic analysisCyber threat intelligenceLinguistic model
The invention discloses a network threat knowledge automatic extraction method, electronic equipment and a storage medium, and the method comprises the following steps executed by a computer hardware system: collecting threat intelligence data related to an APT organization from a multi-source network security text, and processing the threat intelligence data to generate a standardized corpus; using the pre-training sentence vector model to generate semantic embedding for a corpus input text and a manual annotation example library text, and retrieving similar examples to construct an ICL prompt template; inputting a large language model subjected to LoRA fine tuning, and extracting structured triples of multiple types of entities and semantic relationships; generating standardized entity nodes and updated relation information by adopting semantic aggregation; and constructing an APT organization network threat intelligence knowledge graph and outputting a structured file. The method provides key technical support for APT attack tracing, threat situation awareness and automatic security policy generation.
Owner:GUIZHOU UNIV

Network security situation awareness and analysis platform based on AI

The invention discloses a network security situation awareness and analysis platform based on AI, and relates to the technical field of network security situation awareness and analysis, and the platform comprises a multi-source data collection module which integrates flow, logs, assets and threat intelligence data, and carries out encryption transmission and standardization; the data preprocessing module purifies and optimizes data, and guarantees data quality and sensitive information security; the AI situation awareness analysis module extracts features through a deep learning model, dynamically evaluates the situation and identifies threats; the threat early warning and decision-making module triggers graded early warning and generates a targeted emergency response scheme; the visual display and interaction module displays information in multiple dimensions and supports query and report generation; and the data storage and tracing module adopts a mixed storage architecture, so that the data security and traceability are ensured. The platform integrates multi-source data and realizes situation accurate perception and intelligent decision by means of an AI technology; the early warning is accurate, the visual interaction is convenient, and the intelligent and efficient level of network security protection is comprehensively improved.
Owner:HUNAN CONGMAO TECH CO LTD

Power network attack chain dynamic deduction and intelligent response process method, system and device based on deep reinforcement learning, and medium

The invention discloses a power network attack chain dynamic deduction and intelligent response process method, system and device based on deep reinforcement learning and a medium, and belongs to the technical field of network security and power system protection. Multi-modal data is aligned and normalized, an event view cache is constructed, and the generalization detection capability on process camouflage and memory injection attacks is improved through a federated learning collaborative detection mechanism; based on the event view cache and historical threat intelligence, generating a dynamic attack knowledge graph, constructing a deep reinforcement learning model taking the attack knowledge graph as an environment, calculating an attack influence index by using a Bayesian network, and generating a differentiated security response instruction; and realizing attack path backtracking and attack source positioning based on the attack knowledge graph. According to the method, multi-modal data fusion analysis and strategy adaptive updating are realized, and the attack chain identification accuracy and evidence chain construction integrity are remarkably improved.
Owner:GUANGXI POWER GRID CORP

Multi-level power network threat collaborative identification method and system

The invention relates to the technical field of power system network security, in particular to a multi-level power network threat collaborative identification method and system, and the method comprises the steps: obtaining an attack behavior data set according to multi-source attack data collected by transformer substations of different voltage levels in a multi-level power network, generating an attack semantic feature set based on the attack behavior data set; analyzing the real-time threat intelligence data based on the attack semantic feature set, and extracting cross-site time sequence mode features; obtaining a coordination action event sequence according to the cross-site time sequence mode characteristics; analyzing a threat propagation path of the attack load among different substations according to the coordination action event sequence to obtain a cross-site threat association feature map; and obtaining a threat association identification result according to the cross-site threat association feature map. According to the method, the attack load characteristics of the multi-level power network and cross-site time sequence cooperative behavior analysis are fused, so that the cross-site cooperative attack behavior is efficiently identified, and the network security protection capability of the power system is improved.
Owner:STATE GRID ZHEJIANG ELECTRIC POWER CO LTD HANGZHOU POWER SUPPLY CO

Network security situation assessment processing method and system

The invention relates to the field of network security, and discloses a network security situation assessment processing method and system.The method comprises the steps that firstly, network equipment states, user behavior data, access logs and threat intelligence are collected in real time through a property management system, and data security is guaranteed through a lightweight encryption protocol and an anonymization technology; secondly, dynamically calculating a network security risk value based on a multi-dimensional analysis model, evaluating the current network situation, and verifying the legality of the equipment through a bidirectional authentication mechanism; and finally, according to an evaluation result, automatically executing abnormal equipment isolation and malicious traffic disposition blocking strategies, and simultaneously triggering an alarm to notify a manager. According to the method, the equipment vulnerability, the behavior abnormality and the threat activeness are dynamically quantified through the multi-dimensional analysis model, comprehensive evaluation of the network security situation is realized in combination with a network topology complexity factor, and the risk identification accuracy and the network security protection capability are remarkably improved.
Owner:HUAINAN UNITED UNIVERSITY +1

Threat Intelligence Systems

A threat intelligence system utilising language models to generate queries for external threat intelligence systems, receive and filter responses, and generate alerts and reports using further language models.
Owner:VARONIS SYSTEMS INC

Dynamic cybersecurity policy management based on contextual adaptive learning

A computerized system for dynamic cybersecurity policy using AI-based contextual adaptive learning includes an AI system that evaluates business contexts, risk tolerance, and productivity impact to generate threat intelligence assessments. The system includes a Contextual Adaptive Learning module that dynamically adjusts cybersecurity policies based on threat assessments to create security workflows. A Cybersecurity Mesh Development module that integrates policies across security frameworks. A Dynamic Scenario Catalog module that updates policy adjustments based on threat intelligence. An Automated Workflow Orchestration module that creates and refines security workflows for optimal efficiency. A Policy Recommendation and Automation module that generates prioritized security recommendations and automates policy changes based on organizational risk profiles and current security controls. This system harmonizes security policies while considering business context, risk, and productivity impacts.
Owner:PURATHEPPARAMBIL SANTHOSH KUNJAPPAN +2

Counter measure strategy construction method and system based on attack intelligence

The invention belongs to the technical field of network security, and discloses a countering measure strategy construction method and system based on attack intelligence. According to the method, firstly, multi-source attack intelligence is fused, and a causal time sequence attack knowledge graph is constructed; then, mapping the atlas on a digital twinborn model based on the IEC 62443 standard, constructing a Bayesian attack graph, and quantifying the risk of each attack path; then, taking the risk, the cost and the operation influence as multiple targets, and adopting an NSGA-II algorithm to generate a Pareto optimal countering strategy set; further, an optimal robust strategy is selected from the strategy set by solving the Stackelberg safety game model; and finally, explaining the decision process by using an interpretable AI technology. According to the method, the problems of passive threat intelligence analysis, static risk assessment, sub-optimal strategy selection and opaque decision-making process in the prior art are solved, and active, quantitative, optimal and credible defense decision-making for the key infrastructure is realized.
Owner:GUANGXI POWER GRID CORP

Data security protection method and system combined with big data analysis

The invention discloses a data security protection method and system combined with big data analysis, and relates to the field of data security protection, and the method comprises the steps: building a multi-dimensional data collection and fusion data set according to API access records, external threat intelligence and context metadata association data; based on an isolated forest algorithm, calculating a sample path length to evaluate a behavior anomaly probability score; risk indexes of external threats, data sensitivity and permission exceptions are quantified respectively; constructing a data security risk comprehensive assessment model based on a weighted summation algorithm, and updating and optimizing the weight in the model by using a gradient boosting tree algorithm; and according to an output result of the data security risk comprehensive assessment model, setting a security risk level, and according to the security risk level, dynamically responding to a protection measure. The method has the advantages that continuous and dynamic risk assessment and automatic response to third-party data access behaviors are realized by fusing multi-source data and an intelligent algorithm.
Owner:COLLEGE OF MOBILE TELECOMM CHONGQING UNIV OF POSTS & TELECOMM

Network security script arrangement method based on LLM enhanced RL

A network security script arrangement method based on LLM enhanced RL comprises the following steps: 1) LLM dynamically expands a to-be-selected strategy atom set based on a security threat scene: firstly, performing semantic similarity retrieval on input security threat intelligence by using a vector library, and matching an optimal defense strategy atom in a knowledge library; the context understanding capability of the LLM is then utilized to implement semantic understanding and reasoning on the candidate atom set, generating new policy atoms complementary to the defense. 2) RL refers to LLM atomic action preference to optimize a script generation strategy, and self-adaptive security arrangement of a complex network environment is realized: firstly, a security script graph model based on strategy atoms is adopted, and multiple constraints corresponding to nodes and edges in the graph model are abstracted on the basis of security arrangement definition; and then, a composite reward function is adopted to model a linear programming function for the multi-constrained security script arrangement problem, so that multi-dimensional optimization of defense efficiency and execution cost is realized.
Owner:NANJING TECH UNIV

Broadcasting and television network security operation method and system based on large model

PendingCN120750602ABiological modelsSecuring communicationCyber threat intelligenceNoise (radio)
The invention discloses a broadcast television network security operation method and system based on a large model, and the method comprises the steps: collecting log, network flow and terminal behavior data in real time, storing the data in a Kafka message queue, receiving the data through an AI intelligent noise reduction module, extracting alarm text semantic features through an XLM-ROBERTa model, and carrying out the noise filtering through combining with a multi-classification model, thereby obtaining high-value data; inputting the high-value data and security document knowledge corresponding to the network threat intelligence into an RAG knowledge base module, generating enhanced context information data through knowledge extraction, vectorization storage and similarity retrieval, inputting the enhanced context information data into a cue word of a reply model, and outputting a first threat analysis reply; inputting the high-value data and the first threat analysis reply into a multi-model MOE architecture, distributing tasks through a gating network, integrating expert network output results, and generating a second threat analysis reply and a corresponding attack thermodynamic diagram; and executing feedback optimization operation of the corresponding module based on the second threat analysis reply, thereby improving the safety operation efficiency of the broadcast television network.
Owner:NINGBO RADIO & TELEVISION GRP

Network security validity verification and quantitative evaluation method and system

The embodiment of the invention provides a network security validity verification and quantitative evaluation method and system, and relates to the technical field of network security, and the method comprises the steps: obtaining global dynamic threat intelligence and a multi-dimensional global network security risk data source, and carrying out the preprocessing; constructing a global feature engineering system based on heterogeneous information network atlas and sequence analysis, forming a feature vector matrix, and mapping the feature vector matrix into an index state vector; inputting the feature vector matrix, the index state vector and the external environment information vector into an evaluation model, dynamically adjusting the weight of the feature vector matrix of each dimension, and outputting the validity score of each safety control point; based on the score, calculating a safety effectiveness index based on a time decay factor; identifying a weak link based on the index, and performing simulation verification to obtain a simulation attack actual measurement result; and an error vector is constructed based on the result and the validity score, and parameter adjustment and weight calibration are carried out. According to the scheme, the accuracy and the real-time performance of network security evaluation are improved.
Owner:YUANBAO TECH

Vehicle-mounted network security threat sensing system and method based on edge and cloud collaboration

The invention provides a vehicle-mounted network security threat sensing system and method based on edge and cloud collaboration, and belongs to the technical field of vehicle network security. Comprising the following steps: S1, collecting vehicle multi-modal data through an edge layer; s2, preprocessing the multi-modal data of the vehicle; s3, performing feature extraction on the preprocessed vehicle multi-modal data to obtain a high-dimensional feature vector; s4, calculating a threat confidence score based on the high-dimensional feature vector; s5, performing hierarchical response decision based on the threat confidence score and a predefined response strategy library, and generating hierarchical response data; s6, extracting threat metadata based on the hierarchical response data; s7, performing global association analysis based on the threat metadata, and upgrading a defense system; and S8, based on the global threat intelligence and the upgraded defense system, carrying out edge layer updating, and then skipping to S1. The method is beneficial to eliminating response delay, relieving network bandwidth pressure and optimizing cloud computing resource load.
Owner:上海星宇智行技术有限公司

Network security analysis system based on AI algorithm

The invention belongs to the technical field of network security, and particularly relates to a network security analysis system based on an AI algorithm. Comprising a data acquisition and preprocessing module, an abnormal behavior characteristic index construction module, a safety mode evolution law index construction module and a threat risk comprehensive evaluation module. According to the system, multi-source heterogeneous data such as network flow, equipment logs, threat intelligence and user behaviors are analyzed through deep learning, a graph neural network and an attention mechanism, potential attack time periods are recognized in real time, the threat evolution trend is predicted, and dynamic early warning is achieved by fusing multi-dimensional risk factors. Compared with a traditional detection mode based on rules, the method has higher unknown threat detection capacity, interpretability and real-time performance, the network security protection level can be greatly improved, and the method is suitable for various complex network environments.
Owner:SHANDONG INTERNET MEDIA GRP CO LTD

Generation of threat intelligence based on cross-customer data

Data platforms described herein are configured to monitor a compute environment and generate threat intelligence data based on cross-customer data. Such a data platform may access a plurality of customer datasets collected from a plurality of compute environments, aggregate the plurality of customer datasets into an aggregate dataset, and generate, based on the aggregate dataset, one or more indicators indicative of one or more security threats against one or more compute assets within the plurality of compute environments. The data platform may then detect an occurrence of the one or more indicators within a particular compute environment and perform, based on the occurrence of the one or more indicators, a security response operation with respect to the particular compute environment.
Owner:FORTINET INC

Entity relationship identification method based on rotation position coding and global pointer network

The invention discloses an entity relationship recognition method based on rotation position coding and a global pointer network, which comprises the following steps of: coding an input Chinese threat intelligence text by utilizing a pre-training language model fused with the rotation position coding, and generating context semantic representation with enhanced position perception capability; based on the context semantic representation, decoding all possible entity spans and types thereof in parallel in a two-dimensional grid space through a global pointer network to generate an entity set; for a target entity pair in the entity set, constructing a structured input sequence containing entity position information; processing the structured input sequence by using a double-attention coding mechanism; and based on the output of the double-attention coding mechanism, determining the relationship type between the target entity pairs through a relationship classification module. According to the method, precise decoding of nested entities and robust recognition of cross-language terms are realized through geometric space mapping and a dynamic boundary optimization mechanism.
Owner:Chinese People's Liberation Army Cyberspace Force Information Engineering University

Network security linkage response system based on distributed intrusion detection

PendingCN121125355ASecuring communicationHigh level techniquesDistributed intrusion detectionAttack
The invention discloses a network security linkage response system based on distributed intrusion detection, which belongs to the technical field of network security, aims to improve the comprehensiveness of network threat detection and the timeliness of response, and comprises a distributed lightweight probe, an edge preprocessing and initial judgment module, a central depth analysis module, an intelligent linkage response module and a unified management visualization module. The distributed lightweight probe module collects network security data of each network node; the edge preprocessing and initial judgment module processes the network security data and reports the network security data after initial abnormal detection; the central deep analysis module fuses and associates the reported preprocessed data, and obtains a threat analysis result in combination with AI model analysis, external threat intelligence comparison and attack chain reduction; the intelligent linkage response module matches a preset strategy execution scheme based on the threat analysis result and feeds back an effect; and the unified management visualization module is responsible for configuration management, result display and alarm. According to the invention, accurate identification and rapid linkage response of network threats are realized, and the network security is effectively guaranteed.
Owner:WHARF TECHNOLOGY (HUBEI) CO LTD