Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

321 results about "Threat intelligence" patented technology

Threat intelligence is the analysis of internal and external threats to an organization in a systematic way. The treats that threat intelligence attempts to defend against include zero-day threats, exploits and advanced persistent threats (APTs).

Network security situation awareness and analysis platform based on AI

The invention discloses a network security situation awareness and analysis platform based on AI, and relates to the technical field of network security situation awareness and analysis, and the platform comprises a multi-source data collection module which integrates flow, logs, assets and threat intelligence data, and carries out encryption transmission and standardization; the data preprocessing module purifies and optimizes data, and guarantees data quality and sensitive information security; the AI situation awareness analysis module extracts features through a deep learning model, dynamically evaluates the situation and identifies threats; the threat early warning and decision-making module triggers graded early warning and generates a targeted emergency response scheme; the visual display and interaction module displays information in multiple dimensions and supports query and report generation; and the data storage and tracing module adopts a mixed storage architecture, so that the data security and traceability are ensured. The platform integrates multi-source data and realizes situation accurate perception and intelligent decision by means of an AI technology; the early warning is accurate, the visual interaction is convenient, and the intelligent and efficient level of network security protection is comprehensively improved.
Owner:HUNAN CONGMAO TECH CO LTD

Dynamic cybersecurity policy management based on contextual adaptive learning

A computerized system for dynamic cybersecurity policy using AI-based contextual adaptive learning includes an AI system that evaluates business contexts, risk tolerance, and productivity impact to generate threat intelligence assessments. The system includes a Contextual Adaptive Learning module that dynamically adjusts cybersecurity policies based on threat assessments to create security workflows. A Cybersecurity Mesh Development module that integrates policies across security frameworks. A Dynamic Scenario Catalog module that updates policy adjustments based on threat intelligence. An Automated Workflow Orchestration module that creates and refines security workflows for optimal efficiency. A Policy Recommendation and Automation module that generates prioritized security recommendations and automates policy changes based on organizational risk profiles and current security controls. This system harmonizes security policies while considering business context, risk, and productivity impacts.
Owner:PURATHEPPARAMBIL SANTHOSH KUNJAPPAN +2

Data security protection method and system combined with big data analysis

The invention discloses a data security protection method and system combined with big data analysis, and relates to the field of data security protection, and the method comprises the steps: building a multi-dimensional data collection and fusion data set according to API access records, external threat intelligence and context metadata association data; based on an isolated forest algorithm, calculating a sample path length to evaluate a behavior anomaly probability score; risk indexes of external threats, data sensitivity and permission exceptions are quantified respectively; constructing a data security risk comprehensive assessment model based on a weighted summation algorithm, and updating and optimizing the weight in the model by using a gradient boosting tree algorithm; and according to an output result of the data security risk comprehensive assessment model, setting a security risk level, and according to the security risk level, dynamically responding to a protection measure. The method has the advantages that continuous and dynamic risk assessment and automatic response to third-party data access behaviors are realized by fusing multi-source data and an intelligent algorithm.
Owner:COLLEGE OF MOBILE TELECOMM CHONGQING UNIV OF POSTS & TELECOMM

Network security validity verification and quantitative evaluation method and system

The embodiment of the invention provides a network security validity verification and quantitative evaluation method and system, and relates to the technical field of network security, and the method comprises the steps: obtaining global dynamic threat intelligence and a multi-dimensional global network security risk data source, and carrying out the preprocessing; constructing a global feature engineering system based on heterogeneous information network atlas and sequence analysis, forming a feature vector matrix, and mapping the feature vector matrix into an index state vector; inputting the feature vector matrix, the index state vector and the external environment information vector into an evaluation model, dynamically adjusting the weight of the feature vector matrix of each dimension, and outputting the validity score of each safety control point; based on the score, calculating a safety effectiveness index based on a time decay factor; identifying a weak link based on the index, and performing simulation verification to obtain a simulation attack actual measurement result; and an error vector is constructed based on the result and the validity score, and parameter adjustment and weight calibration are carried out. According to the scheme, the accuracy and the real-time performance of network security evaluation are improved.
Owner:YUANBAO TECH

Generation of threat intelligence based on cross-customer data

Data platforms described herein are configured to monitor a compute environment and generate threat intelligence data based on cross-customer data. Such a data platform may access a plurality of customer datasets collected from a plurality of compute environments, aggregate the plurality of customer datasets into an aggregate dataset, and generate, based on the aggregate dataset, one or more indicators indicative of one or more security threats against one or more compute assets within the plurality of compute environments. The data platform may then detect an occurrence of the one or more indicators within a particular compute environment and perform, based on the occurrence of the one or more indicators, a security response operation with respect to the particular compute environment.
Owner:FORTINET INC

Entity relationship identification method based on rotation position coding and global pointer network

The invention discloses an entity relationship recognition method based on rotation position coding and a global pointer network, which comprises the following steps of: coding an input Chinese threat intelligence text by utilizing a pre-training language model fused with the rotation position coding, and generating context semantic representation with enhanced position perception capability; based on the context semantic representation, decoding all possible entity spans and types thereof in parallel in a two-dimensional grid space through a global pointer network to generate an entity set; for a target entity pair in the entity set, constructing a structured input sequence containing entity position information; processing the structured input sequence by using a double-attention coding mechanism; and based on the output of the double-attention coding mechanism, determining the relationship type between the target entity pairs through a relationship classification module. According to the method, precise decoding of nested entities and robust recognition of cross-language terms are realized through geometric space mapping and a dynamic boundary optimization mechanism.
Owner:Chinese People's Liberation Army Cyberspace Force Information Engineering University

Power metering system network security situation analysis method and system based on big data

The invention provides an electric power metering system network security situation analysis method and system based on big data, and relates to the technical field of electric power system information security. According to the method, network traffic, system logs, security alarms, asset information, vulnerability records and external threat intelligence are collected, a security data lake is constructed, and security situation factors are extracted; outputting an anomaly detection result and a threat classification result by using the unsupervised anomaly detection model and the supervised threat classification model; calculating an asset security risk value and an overall security risk value by combining the vulnerability severity and the asset importance, and generating an overall security index, an attack threat level and a vulnerability level; and a time sequence prediction model is further constructed based on the network security situation indexes, and future situation prediction and security early warning are realized. According to the invention, comprehensive perception, accurate analysis and active defense of the network security situation can be realized.
Owner:HARBIN INSTITUTE OF TECHNOLOGY (SHENZHEN) (INSTITUTE OF SCIENCE AND TECHNOLOGY INNOVATION HARBIN INSTITUTE OF TECHNOLOGY SHENZHEN)

Network security protection strategy generation method based on multi-source data fusion

The invention discloses a network security protection strategy generation method based on multi-source data fusion. The method comprises the following steps of collecting security data of a network side, a terminal side, an identity side, an asset and service topology side and an external threat intelligence side, and performing time alignment and missing supplementation; standardly generating an evidence unit sequence and an evidence credibility vector, and aggregating and constructing an evidence unit long sequence according to an entity and a sliding time window; inputting the evidence unit long sequence, the evidence credibility vector and the service topology condition vector into an improved Mamba-2 model, and outputting an attack intention distribution, risk situation embedding and key evidence reference set; generating a strategy candidate set; optimizing an output strategy packet under the constraint of a service link, a change window and compliance auditing; executing protection and monitoring indexes, and if a rollback condition is met, performing rollback; and collecting feedback update credibility mapping parameters and trigger thresholds. According to the invention, closed-loop self-adaptive protection is formed, and the strategy effectiveness and the service continuity guarantee capability are improved.
Owner:FUJIAN ZHENGYU ELECTRIC POWER TECHNOLOGY SERVICE CO LTD

Self-adaptive firewall rule generation method and device based on real-time threat intelligence

The invention relates to a self-adaptive firewall rule generation method and device based on real-time threat intelligence, and the method comprises the steps: carrying out the semantic analysis of a threat intelligence text, extracting attack indexes and attack technique and tactics labels, and generating an intelligence triple set and an attack technique and tactics label set; calling a language model to generate candidate rules based on an intelligence analysis result, carrying out credibility scoring, intercepting a low-scoring rule as a high-risk illusion rule, and entering other rules into a to-be-verified set; constructing a digital twinborn shadow sub-domain to perform real-time traffic verification on the rule set to be verified, and dividing the rule set to be verified into an effective rule set and an invalid rule set according to a verification result; constructing a rule dependence graph based on the invalid rule set to perform pollution traceability, and adding nodes with excessive pollution into an isolation list; and cleaning the historical training samples based on the isolation list and the interception rule log, and performing incremental training on the language model to generate an updated model.
Owner:QUANZHOU YANLING INFORMATION TECHNOLOGY CO LTD

Dynamic authority control and behavior auditing method and system for privileged account

The invention relates to a privileged account-oriented dynamic authority control and behavior auditing method and system, which integrate operation sequence analysis, environmental threat intelligence and user behavior baselines, construct a behavior DNA model and realize accurate real-time risk scoring. A transient dynamic token is adopted to realize permission minimization, a token fusing mechanism is initiated to realize real-time interruption of high-risk operation, suspicious operation intention verification is performed through a mirror image sandbox, and a virtual pressure test is introduced to actively detect potential threats. A full-link digital twin system is established, it is ensured that auditing records cannot be tampered in combination with a distributed consensus auditing account book, and attack chain visualization and operation scene accurate playback are supported. According to the scheme, the problems of permission flooding, extensive management and control, weak auditing and the like existing in traditional privileged account management are effectively solved, precise management and control, intelligent early warning and credible traceability of privileged behaviors are realized, and comprehensive protection is provided for organizing core assets.
Owner:SICHUAN SHANGXIN PAILA TECHNOLOGY CO LTD

Network spoofing defense method and system based on AI virtual topology generation

The embodiment of the invention provides a network spoofing defense method and system based on AI virtual topology generation, and the method comprises the steps: continuously collecting multi-source heterogeneous data in a network, and constructing and dynamically updating a real network topology portrait based on the multi-source heterogeneous data; on the basis of a generative adversarial network model, adversarial training is carried out by taking the real network topology portrait as a training sample, the structure and characteristics of a real network are learned, and a dynamically changing simulation virtual network topology is generated; seamless fusion and dynamic deployment are carried out on the simulation virtual network topology and the real network, and a trapping environment is constructed; monitoring and recording an attack behavior of an attacker in the trapping environment, and performing deep interaction analysis on the attack behavior and generating threat intelligence; and based on the threat intelligence, dynamically optimizing a deception strategy and executing a closed-loop control response. According to the embodiment of the invention, the virtual topology which is highly similar to a real network but is completely imaginary can be dynamically generated by utilizing artificial intelligence.
Owner:HUANENG POWER INT INC +1

Cybersecurity threat network traffic generation with large language models

A security feed normalizer aggregates and normalizes threat intelligence data across security feeds and extracts threat descriptors of cybersecurity threats from the aggregated / normalized data. A first large language model (LLM) determines whether each threat descriptor is informative, i.e., comprises sufficient information for reproducing / generating network traffic of the corresponding cybersecurity threat. For informative threat descriptors, a second LLM generates network traffic for the corresponding cybersecurity threats. The generated network traffic is used for subsequent remediation of corresponding threats.
Owner:PALO ALTO NETWORKS INC

Threat detection and self-evolution defense system for AI electric power industrial control network

The invention relates to the technical field of power system network security, and discloses an AI power industrial control network threat detection and self-evolution defense system, which comprises a data acquisition and preprocessing module used for acquiring and preprocessing multi-source heterogeneous data of a power industrial control network; the time sequence anomaly detection module is used for carrying out time sequence anomaly detection on the standardized fusion feature vector sequence; the topology anomaly detection module is used for carrying out topology anomaly detection on the standardized fusion feature vector sequence; the comprehensive anomaly judgment module is used for calculating an anomaly detection threshold value, calculating a comprehensive anomaly score and comparing the anomaly detection threshold value with the comprehensive anomaly score; the threat intelligence analysis module is used for constructing an electric power industrial control threat knowledge graph and performing threat intelligence analysis based on a comprehensive anomaly detection result; the defense strategy optimization module is used for performing defense strategy optimization; the self-evolution learning module is used for driving continuous evolution of threat detection and defense strategies; the safety protection capability of the electric power industrial control network is effectively improved.
Owner:ZHEJIANG XINZHI DIGITAL CARBON TECH CO LTD

Gateway port on-off control method, equipment and medium

The invention provides an on-off control method and device for a gateway port and a medium. The on-off control method comprises the steps of obtaining historical access log data and threat intelligence data of a target port in a gateway; based on the historical access log data and the threat intelligence data, performing time sequence analysis by using a pre-trained long-short-term memory network model to obtain a predicted security access time period of the target port in a future preset time period; generating a temporary port exposure preset rule of the target port according to the predicted security access time period; determining a traffic feature vector of the real-time traffic data packet of the target port; using a preset deep reinforcement learning agent to determine an on-off control instruction for the target port based on the traffic feature vector and a temporary port exposure preset rule; and executing the on-off control instruction to modify an access control list state of the gateway firewall to the target port. According to the method and the device, dynamic and refined gateway port on-off control can be realized, so that the service flexibility and security are considered.
Owner:LINGBO TECH (BEIJING) CO LTD

APT network attack identification method and system

The embodiment of the invention discloses an APT (Advanced Persistent Threat) network attack identification method, which comprises the following steps: collecting multi-source data from a plurality of data sources, and filtering current attack behavior data from the multi-source data; performing multi-dimensional similarity calculation on the current attack behavior data and the APT organization intelligence in the multi-modal threat knowledge graph to obtain a comprehensive similarity, the multi-modal threat knowledge graph being obtained by modeling after the multi-dimensional attack data and the threat intelligence are fused; nodes in the multi-modal threat knowledge graph are used for representing APT organizations, TTP, used tools and attack targets, and edges connected with the nodes are used for representing relationships among entities represented by the nodes; and based on the comprehensive similarity and the multi-modal threat knowledge graph, performing attribution reasoning on the APT organization of the current attack behavior data to obtain the identity information of the attacker. According to the method, unknown threats can be identified, the identity information of an attacker can be obtained through accurate reasoning, and the utilization rate of intelligence is improved.
Owner:QI AN XIN TECHNOLOGY GROUP INC

Threat intelligence data processing method and related equipment

The embodiment of the invention provides a threat intelligence data processing method and related equipment. The method comprises the following steps: acquiring an associated knowledge graph constructed based on multi-source threat intelligence data and network asset data; acquiring a real-time operation data flow in the monitoring network, determining asset data associated with the real-time operation data flow based on the associated knowledge graph, and performing priority matching based on the corresponding comprehensive risk value to obtain a priority corresponding to the real-time operation data flow; generating context associated data corresponding to the real-time operation data flow based on the associated asset data, and obtaining standard event data based on the corresponding priority, the real-time operation data flow and the context associated data; and matching the standard event data based on the at least one detection research and judgment rule corresponding to the research and judgment label to obtain the target research and judgment label, and generating the target processing instruction based on the processing strategy corresponding to the target research and judgment label, thereby improving the threat response efficiency and the closed-loop processing accuracy.
Owner:PENG CHENG LAB

Automated cyber security and regulatory risk management system using natural language processing

This invention provides an automated system for managing cyber security and regulatory risks. It retrieves internal documents from platforms like Google Drive and OneDrive, and external documents from trusted sources via RSS feeds. Documents are stored in centralized locations with lifecycle management, enriched with contextual labels, and used to augment and fine-tune a language model. Real-time threat intelligence and news feeds are integrated, enabling the system to analyze security advisories and regulatory requirements, generating actionable insights and recommendations. The system integrates with workflow management tools like Jira for tracking work items and provides a natural language interface for ad-hoc user interaction. This comprehensive solution enhances operational efficiency, reduces manual efforts, and ensures timely responses to emerging threats and regulatory changes.
Owner:SZIMMETAT OLIVER

Network security operation method and system, electronic equipment and storage medium

The invention discloses a network security operation method and system, electronic equipment and a storage medium, and relates to the field of network security. The method comprises the following steps: collecting multi-source heterogeneous data in real time through a distributed sensor network, and processing the multi-source heterogeneous data to generate a standardized data set; performing feature extraction on the standardized data set to generate a feature vector fusing space-time relevance and behavior semantics; matching the feature vector with features of known threats in a threat intelligence library, and if matching succeeds, generating a preliminary alarm according to a target known threat corresponding to the matched target feature; performing false alarm filtering on the preliminary alarm, and generating a first optimization alarm list of the known threat of the target; and triggering a predefined first response strategy according to the threat level of the first optimization alarm list. By implementing the technical scheme provided by the invention, an intelligent operation scheme capable of fusing multi-source data, reducing the false alarm rate and improving the unknown threat detection capability can be obtained.
Owner:ZHUHAI JINGWEI TIANDI COMM TECH CO LTD

URL (Uniform Resource Locator) security analysis method and device for end-side large language model and medium

PendingCN121508975ABiological modelsSecuring communicationLinguistic modelClosed loop analysis
The invention discloses a URL (Uniform Resource Locator) security analysis method and device for an end-side large language model and a medium, and belongs to the field of network and information security. The method comprises the steps of collecting multi-modal data such as a URL analysis structure, DNS / certificate metadata, front-end code sampling, an OCR text and a dynamic behavior event sequence; performing exponential decay weighted aggregation on the dynamic events in the sliding time window; generating a static structure feature, a text semantic feature and a threat intelligence similarity based on the multi-modal data; fusing the multi-modal features by adopting a gating attention mechanism; inputting the fusion features and the readable context into an end-side large language model, and calling a security analysis tool set under limited decoding; a risk score and a minimum sufficient evidence are obtained through two-stage scoring; and executing an end-side security policy according to the scoring threshold value and leaving a trace by using a JSONL structure. According to the method, in-end closed-loop analysis is realized, the detection accuracy is remarkably improved, and the method is suitable for various deployment scenes such as mobile terminals and edge gateways.
Owner:中邮建技术有限公司

Threat intelligence confidence research and judgment system and method based on multi-source feature fusion

The invention discloses a threat intelligence confidence research and judgment system and method based on multi-source feature fusion. Comprising a multi-source data acquisition module, a data preprocessing module, a feature extension and enhancement module, a feature screening and weight initialization module, an exception and threat preliminary screening module, a feature fusion and association modeling module, an attack scene association and context extension module, a confidence quantitative calculation module and a research and judgment result output and application module. A model verification and feedback module; and a threat information archiving and management module. According to the method, comprehensive acquisition and deep fusion of multi-source heterogeneous data are realized, and the information isolation of a single data source is broken; a multi-dimensional research and judgment result confidence quantitative model is constructed, so that the research and judgment result is more objective and comparable; the feature weight and the association logic can be flexibly adjusted according to different attack scenes, and the accuracy of threat research and judgment under multiple scenes is improved; and through a closed-loop optimization mechanism, the research and judgment precision is ensured to be dynamically improved along with data iteration and scene change.
Owner:北京国御网络安全技术有限公司

Network security risk prediction and prevention method and system based on big data

PendingCN121396539ABiological modelsSecuring communicationCritical information infrastructureInternet traffic
The invention relates to the technical field of information, and discloses a network security risk prediction and prevention method and system based on big data, and the method and system comprise a data collection module, a data processing module, a risk prediction module, a strategy generation module, a response execution module, and an optimization feedback module. Network traffic, system logs, user behaviors and threat intelligence data are converged in real time through a distributed acquisition module, a high-dimensional feature vector is generated by fusing time sequence, statistics and semantic features through feature engineering, automatic responses such as traffic filtering and access control are executed, and an incremental learning mechanism dynamic optimization model is constructed; according to the method, multi-source data fusion analysis is realized, the attack detection coverage rate and response timeliness are improved, real-time risk prediction and dynamic defense are supported, the high-risk attack interception efficiency is improved, continuous evolution of the model is realized through incremental learning, and the novel attack detection rate and the resource efficiency are improved in a breakthrough manner; and an efficient active defense capability is provided for the key information infrastructure.
Owner:YANGJIANG YUEFENG TECHNOLOGY CO LTD

Cloud honey point dynamic arrangement method and system based on software-defined spoofing defense

The invention provides a cloud honey point dynamic arrangement method and system based on software-defined spoofing defense, and the system comprises a base construction control layer and an execution layer based on software-defined spoofing defense, the control layer comprises a threat sensing unit, a game decision unit and an arrangement control unit, the execution layer comprises a cloud native arrangement unit and a defense resource library; the threat sensing unit collects threat intelligence and generates a structured intelligence object; the game decision-making unit is used for game solving of an optimal response strategy; the arrangement control unit reads the defense strategy state data, generates a strategy configuration instruction according to the optimal response strategy, and issues the strategy configuration instruction to the cloud native arrangement unit; the cloud native arrangement unit responds to the instruction and dispatches a defense resource library to instantiate a Pod comprising a honey point container and a distributed feedback component; the defense resource library is used for maintaining honey point configuration files for generating honey point instances. By applying the system, self-adaptive closed-loop active defense can be realized.
Owner:GUANGZHOU UNIVERSITY +1

Threat intelligence big data governance system and method based on knowledge graph

The invention provides a threat intelligence big data governance system and method based on a knowledge graph, and relates to the field of network security, the system comprises a data acquisition module, an entity extraction module, a knowledge graph construction module, a graph governance module, a graph evolution module and an output module; according to the application, through multi-module cooperation, multi-source heterogeneous threat intelligence is standardized, then entities are extracted and ambiguity is resolved, and a structured knowledge graph is constructed; redundant contradictions are eliminated through governance and optimization, credibility is calibrated, timeliness and accuracy of information are guaranteed in combination with time decay and a feedback mechanism, and finally multi-form output supports downstream application. The problems of single processing, no context and difficulty in distinguishing redundant contradictions in the prior art are effectively solved, the credibility, integrity and availability of threat intelligence are remarkably improved, the false alarm rate is reduced, and the data processing efficiency and the downstream security defense effectiveness are improved.
Owner:HANGZHOU DBAPPSECURITY CO LTD

Network security knowledge graph construction method and system

The invention relates to the technical field of network security, in particular to a network security knowledge graph construction method and system, and the method comprises the following steps: extracting information from original network traffic, logs and threat intelligence, extracting attack features, classifying and storing the attack features in a knowledge base, screening high-risk nodes, judging weak points, generating dynamic keys, and distributing and storing the dynamic keys. The method comprises the following steps of: extracting attack characteristics, carrying out logic classification, constructing a multi-dimensional associated security data system, identifying a threat path and a high-risk node, combining abnormal detection and path complexity comparison, encrypting basic data, verifying and decrypting, adjusting a security policy rule according to an environment, and executing dynamic adjustment of a network security protection policy. According to the method, hidden weak points are accurately judged, a dynamic key generation and distribution mechanism is adopted, encryption consistency and security are improved, distributed encryption exchange and real-time verification are matched, confidentiality and integrity of data transmission and storage are guaranteed, protection self-adaptive adjustment is achieved according to an environment state matching strategy, and response efficiency and flexibility are improved.
Owner:SICHUAN POLICE COLLEGE

Network space security protection capability index measurement method and device, equipment and medium

The invention relates to a cyberspace security protection capability index measurement method, apparatus and device, and a medium. The method comprises the steps of calculating a static protection strength reference based on historical data and an index system; then collecting and analyzing real-time threat intelligence, and quantizing to generate an attacker intention vector; inputting the static protection intensity reference and the attacker intention vector into a non-cooperative game model for deduction, simulating attack-defense interaction and solving an equilibrium strategy, thereby identifying a protection vulnerability set and obtaining an optimal defense strategy suggestion; dynamically correcting the membership degree of each safety index according to the vulnerability point and the intention of an attacker; and fusing the dynamic membership degree and the optimal defense strategy, and performing weighted synthesis to obtain a final safety protection capability index. According to the method, the prospective and dynamic measurement of the network security protection capability is realized by introducing attacker intention analysis and game deduction.
Owner:BEIJING TIANDIHEXING TECH CO LTD +1

Network threat intelligence structured processing method and system based on artificial intelligence

PendingCN121303290AInference methodsSecuring communicationCyber threat intelligenceLinguistic model
The invention relates to the technical field of crossing of artificial intelligence and network security, in particular to a network threat intelligence structured processing method and system based on artificial intelligence. The method comprises the following steps: acquiring unstructured original threat intelligence and performing credibility evaluation on an intelligence source; based on a large language model and knowledge graph enhanced retrieval, a step-by-step analysis plan for original threat intelligence is generated; dynamically calling a tool to execute an information extraction subtask corresponding to each step in the analysis plan to obtain a preliminary extraction result; performing multi-dimensional confidence evaluation on the preliminary extraction result; and taking the preliminary extraction result with the confidence higher than or equal to a threshold as a final result, and outputting the final result in a formatting manner and updating the final result to the knowledge graph. According to the method, the problem that unstructured multi-mode threat intelligence is difficult to convert into structured data which is readable by a machine, self-consistent in logic and capable of being put into actual combat in the prior art is solved, and the improvement of attack chain understanding depth and integrity is realized.
Owner:DATA SPACE RES INST

Data full-process monitoring and early warning method in vehicle network interaction scene

The invention provides a data full-process monitoring and early warning method in a vehicle network interaction scene, and relates to the technical field of vehicle network interaction. Threat intelligence and public vulnerability information oriented to a vehicle network interaction platform are associated with identified network assets, modeling is carried out on traffic, power and time sequence characteristics in the processes of vehicle network charging, load prediction and energy interaction, dynamic comparison is carried out on data streams, and risk behaviors in the communication process are found; illegal access, data leakage and transverse attack paths are identified, and a structured attacker portrait is formed; abstracting system assets and data streams into a graph model with probability and time weight, and screening out feasible attack routes; and finally, performing multi-round attack simulation on the selected route based on a domain meta-attack language to obtain global compromise time TTC and contribution degrees of all technologies, and using the contribution degrees to enhance detection rules and processing priorities. And if abnormal traffic or suspicious interaction is monitored, giving risk early warning, and performing automatic disposal according to a set strategy.
Owner:NORTHEASTERN UNIV CHINA +4

Network threat behavior reasoning method and system based on large model retrieval enhancement

The invention discloses a network threat behavior reasoning method and system based on large model retrieval enhancement, and the method comprises the following steps: a computer system executes the following steps: determining a query target and an associated scene or organization by receiving a network threat analysis query request of a user; retrieving related nodes and relationships from the threat intelligence knowledge graph, and generating an initial reasoning sub-graph; calling a GraphRAG framework, and carrying out semantic matching retrieval on a subgraph node context and an external threat intelligence knowledge base to obtain supplementary evidence; constructing a comprehensive prompt template, inputting the large language model subjected to LoRA fine tuning, and generating a conformity ATTamp; reasoning a conclusion of the CK framework; and finally, supplementing the newly added nodes and the relationship to the knowledge graph, and outputting a structured file or a visual result. According to the method, retrieval enhancement and large model reasoning technologies are combined, the problems of cross-document attack chain restoration and complex threat behavior logical reasoning are effectively solved, and the method has remarkable application value in the aspects of threat intelligence tracing, behavior prediction and defense decision assistance.
Owner:GUIZHOU UNIV

Multivariate attack feature recognition method and system based on persistent threat attack

The invention is suitable for the technical field of network security, and provides a multivariate attack feature recognition method and system based on persistent threat attacks, and the method comprises the steps: obtaining a real-time traffic data sequence in a target network environment; performing primary anomaly sensing processing on the real-time traffic data sequence to obtain a suspicious traffic fragment set; executing thinking chain reasoning analysis on the suspicious traffic fragment set, and generating an attack behavior reasoning path comprising multi-stage reasoning steps; performing matching verification on the attack behavior reasoning path and a pre-constructed threat intelligence knowledge base, and determining an attack stage and an attack intention of the persistent threat attack; and generating a multivariate attack feature recognition result according to a matching verification result. According to the method, analysis of advanced persistent threat attack multi-stage features is realized through a thinking chain reasoning mode, and the timeliness and reliability of detection are improved, so that the active protection capability of network security is improved.
Owner:CHINA DATANG CORPORATION SCIENCE AND TECHNOLOGY GENERAL RESEARCH INSTITUTE +1

Threat actor infrastructure profiling using a graph and reputation propagation

A computerized method performs threat actor infrastructure profiling using a graph and a reputation propagation algorithm. A threat intelligence (TI) graph comprising known entities and unknown entities is created based on relationships in telemetry data. Risk scores for the known entities in the TI graph are initialized from a TI database. One or more of the unknown entities are classified using a reputation propagation algorithm based on relationships of the unknown entities with the known entities, and the risk scores for the known entities in the TI graph. A remediation action for the classified unknown entities is recommended. In some examples, the remediation action is automatically initiated for the classified unknown entities and the TI graph is updated in response to the remediation action.
Owner:MICROSOFT TECHNOLOGY LICENSING LLC