Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

97 results about "Threat model" patented technology

Threat modeling is a process by which potential threats, such as structural vulnerabilities can be identified, enumerated, and prioritized – all from a hypothetical attacker’s point of view. The purpose of threat modeling is to provide defenders with a systematic analysis of the probable attacker’s profile, the most likely attack vectors, and the assets most desired by an attacker. Threat modeling answers questions like “Where are the high-value assets?”, “Where am I most vulnerable to attack?”, “What are the most relevant threats?”, and “Is there an attack vector that might go unnoticed?”.

Wireless sensor network environment monitoring system based on Internet of Things and safety protection method

The invention relates to the technical field of the Internet of Things, and discloses a wireless sensor network environment monitoring system and a safety protection method based on the Internet of Things, and the system method comprises the steps: collecting sensing node environment data to generate a multi-dimensional feature matrix, and constructing a safety protection strategy set; setting threat parameter types, and establishing a security threat association model by using historical data; extracting real-time attack features and flow parameters, and generating a dynamic protection instruction set and an optimization scheme in combination with the model; and reconstructing a network node control mechanism to generate a target protection scheme, and dynamically and synchronously calibrating an instruction time sequence. The system comprises a node data acquisition module, a security policy generation module, a threat parameter analysis module, a threat modeling module, a risk assessment module, a protection mechanism reconstruction module and a time sequence synchronization module. Through multi-dimensional feature analysis, dynamic threat modeling, adaptive risk assessment and time sequence encryption synchronization, the security protection capability of the wireless sensor network in a complex environment is improved, and the method is suitable for security protection requirements in the field of Internet of Things environment monitoring.
Owner:JINSI TECH GRP CO LTD

Obstacle avoidance method of robot

The invention relates to the technical field of robot obstacle avoidance methods, in particular to an obstacle avoidance method of a robot. According to the method, a dynamic environment sensing system is constructed through multi-sensor fusion, and a dynamic feature description package and a static environment sketch are generated. The system generates a global navigation route by adopting an improved path planning algorithm, and constructs an obstacle space-time probability distribution map in combination with a multi-hypothesis prediction technology. According to the method, a two-channel intention analysis mechanism is introduced, the motion intention of a target is predicted by analyzing the kinematics characteristics and the biological behavior characteristics of the target, and a four-dimensional space-time threat model is established by fusing a space-time probability graph. And according to the threat level, a hierarchical obstacle avoidance strategy is dynamically generated, wherein the hierarchical obstacle avoidance strategy comprises various response modes such as path fine adjustment, speed cooperative adjustment and emergency channel avoidance. The environment cognition and behavior model is continuously updated through a closed-loop optimization mechanism, and finally safe and smooth autonomous navigation in the high-dynamic man-machine coexistence environment is achieved.
Owner:HUBEI BUSINESS COLLEGE

Method, system, and computer program product for artificial intelligence assisted cybersecurity threat modeling tool

Methods, systems, and computer program products are provided for artificial intelligence assisted cybersecurity threat modeling tool that may include receiving data associated with a security architecture document for a specific software environment, converting the data associated with the security architecture document from a natural language format to a threat modeling data format, generating a plurality of vector embeddings based on the threat modeling data, identifying one or more potential cybersecurity threats based on the plurality of vector embeddings, and mapping the one or more potential cybersecurity threats to one or more corresponding controls that provide a potential mitigation action for the one or more potential cybersecurity threats.
Owner:VISA INTERNATIONAL SERVICE ASSOCIATION

Threat Model Generation Systems

Aspects described herein may automatically generate threat models using large language model (LLM). A computing device may send, to LLM, one or more software modules associated with a computing system. The computing device may request the LLM to generate a threat model of the computing system. The computing device may receive, from the LLM, a first output based on the first prompt comprising first information for a first version of the threat model and a penetration test script for the computing system. The computing device may input, to the LLM, the result of the penetration test together with the LLM's previous output, to facilitate the LLM to generate a refined version of the threat model.
Owner:CAPITAL ONE SERVICES LLC

Multimodal large language model (LLM)-based threat modeling

Disclosed are various approaches for multimodal large language model (LLM) based threat modeling. The multimodal LLM based threat modeling can include a system or method that can input, into a threat modeling multimodal LLM, prompting data that includes audio data, image data, and LLM instructions to generate application security data. The threat modeling multimodal LLM can generate and provide application security data that includes at least one of: threat data, weakness data, security control data, a security risk summarization, an application threat model, or any combination thereof.
Owner:AMERICAN EXPRESS TRAVEL RELATED SERVICES CO INC

Situation awareness and linkage disposal system based on dynamic threat modeling driving

The invention discloses a situation awareness and linkage disposal system based on dynamic threat modeling driving, and the system comprises a security data collection and standardization module which is used for collecting security data of a network, a host and an application layer, and carrying out the standardization processing; the dynamic threat modeling module is used for constructing a dynamic threat model; the threat agent modeling and simulation module is used for modeling each node in the threat attack graph into a threat agent; the parameter optimization module is used for globally optimizing parameters and strategy weights of the Monte Carlo tree search network by using a seagull algorithm; the linkage processing decision module is used for configuring a Monte Carlo tree search network based on the optimal parameter group; the safety equipment scheduling module is used for analyzing the optimal linkage disposal decision scheme; and the disposal effect evaluation and feedback module is used for performing multi-dimensional analysis on the disposal feedback data set. According to the invention, accurate situation awareness and linkage processing are provided for the user.
Owner:SHANGHAI VIDE INFORMATION TECHNOLOGY CO LTD

Client identity authentication security evaluation method and system combined with adversarial sample simulation

The invention provides a client identity authentication security evaluation method and system combined with adversarial sample simulation, and relates to the technical field of information security. According to the invention, end-cloud integrated evaluation is carried out under a white-box and black-box threat model for multi-mode identification objects of human face, voiceprint, fingerprint and behavior characteristics. The method comprises the steps of establishing reference performance through legal samples, generating transferable adversarial input, performing secure injection on a communication layer, calculating a robustness index, performing adaptive optimization, performing differential evaluation on protection effectiveness under protection configuration starting and non-starting, and performing risk grading and reinforcement according to a result. And finally, outputting a reproducible security and compliance conclusion through differential privacy and federal evaluation.
Owner:CHENGDU CHUANGXIN HUATONG INFORMATION TECH CO LTD

A network security threat information early warning method and system based on big data

The application discloses the network security early warning technical field, disclose a kind of network security threat information early warning method and system based on big data, comprising: based on big data collection and integration about network security internal data and external data, natural language processing analysis unstructured threat intelligence, threat entity association is built by knowledge graph;Based on big data of network security threat information and deep learning constructs adaptive threat model, uses convolutional neural network CNN to identify abnormal mode in encrypted traffic;Through long short-term memory network LSTM establishes user-device behavior baseline;In combination with graph neural network GNN, the threat diffusion path is predicted, a threat risk quantization model is developed, and the information risk value is calculated by comprehensively considering the attack success rate, asset value, influence range value and response delay;Based on the information risk value calculated, combined with information risk attenuation factor, risk prediction is carried out on network security threat information.
Owner:江西软件职业技术大学

Threat model assistant for software development

The present disclosure of the various embodiments relates to using a large language model to assistant with the creation of secure code and / or the completion of threat modeling tasks in software development. In one example, a system comprises a computing device configure to identify a prompt that requests generating secure source code for source code with a security vulnerability. A security data source is queried for a security threat embedding. The security threat embedding is received from the security data source and an augmented prompt is generated. The augmented prompt is transmitted to the large language model. A secure source code is received from the large language model and imported into application source code in a software development environment.
Owner:AMERICAN EXPRESS TRAVEL RELATED SERVICES CO INC

Threat modeling using machine learning and context information

Various example embodiments provide for threat modeling using machine learning models and context information, where a threat model is generated based on a threat model diagram for a target system being analyzed for threat risks / scenarios. For an individual threat model generated, a threat scenario (e.g., each individual threat scenario) described in the individual threat model can be processed (e.g., individually processed) by a plurality of machine learning models to determine a set of generic mitigation labels for the threat scenario, where each generic mitigation label corresponds to a generic mitigation strategy for mitigating the threat scenario. The set of generic mitigation labels for the threat scenario with context information can be processed by one or more large language models to generate a set of specific mitigation labels for the individual threat model, where each specific mitigation label corresponds to a specific mitigation strategy.
Owner:SNOWFLAKE INC

Multi-identity security verification system based on big data

The invention relates to the technical field of identity security verification, and discloses a multi-identity security verification system based on big data. The system comprises a verification collection module, a feature construction module, a risk modeling module and a decision engine module, wherein the verification collection module obtains user multi-source biological features, behavior tracks and equipment environment data, and performs preprocessing to generate an initial feature set; the feature construction module extracts spatiotemporal behavior patterns and cross-device association features and fuses the spatiotemporal behavior patterns and the cross-device association features into a multi-dimensional The risk modeling module loads a pre-trained dynamic threat model, carries out real-time risk layering on the multi-dimensional feature matrix, and outputs a risk level identifier and an abnormal feature vector; and the decision engine module calls a corresponding verification strategy library, and generates a multi-factor verification instruction set in combination with the abnormal feature vector. The system realizes comprehensive verification of user identities through multi-source data integration, dynamic risk assessment and precise strategy matching, and adapts to various high-security demand scenes.
Owner:SHENZHEN ZHICHUANG JIACHENG TECH CO LTD

Enterprise information security defense strategy generation method based on adaptive rule engine

The invention discloses an enterprise information security defense strategy generation method based on an adaptive rule engine, and relates to the technical field of network and information security, and the method comprises the steps: carrying out the multi-dimensional feature vectorization processing of real-time security event data, and generating a threat feature vector set; based on the threat feature vector set, constructing a dynamic threat model, calculating a risk assessment score of each threat feature vector, and performing clustering analysis on the threat feature vectors to generate a threat scene classification result and a threat level identifier; inputting the threat scene classification result into an adaptive rule engine to generate an initial defense rule set, and correcting the rule priority of the initial defense rule set in real time through a rule weight dynamic adjustment mechanism to form an adaptive defense rule set; and generating a hierarchical enterprise information security defense strategy according to the self-adaptive defense rule set, and sending the hierarchical enterprise information security defense strategy to an enterprise network. According to the method, the dynamic adaptation capability of defense rules and the hierarchical accuracy of strategy deployment are ensured.
Owner:NANJING CHAOS INTERNET OF THINGS TECH CO LTD

Methods for Constructing Threat Models Based on Sensitive Information from Electricity Price Data

This invention provides a method for constructing a threat model based on sensitive information reverse inference using electricity price data, belonging to the field of smart grid analysis technology. This invention constructs a homogeneous linear equation model between electricity price and admittance matrix based on a DC power flow model and a local marginal price theory model. It extracts node and edge features from power data, inputs them into a dynamic routing encoder, outputs encoded feature sequences of nodes and edges, performs time-series modeling on the encoded features, outputs the grid admittance parameter sequence at each time step, and corrects and optimizes the parameter sequence. A differential privacy mechanism is used to perturb the electricity price data. Combined with the optimized parameter sequence, the sensitive information reverse inference threat model is constructed. This invention utilizes dynamic feature encoding and time-series modeling techniques, combined with a differential privacy strategy, to achieve effective reverse inference of grid admittance parameters based on publicly available data, and also completes privacy protection and risk assessment of electricity price data using the differential privacy strategy.
Owner:国网甘肃省电力公司陇南供电公司

Security threat model optimization system and method based on online self-learning

The invention relates to the technical field of data processing, in particular to a security threat model optimization system and method based on online self-learning, and the system comprises a data collection module which eliminates the electromagnetic interference of a power grid, dynamically adjusts the sampling frequency, and improves the data quality; the feature processing module extracts statistical features and topological features by adopting a dual-channel parallel architecture, and dynamically selects a dimension reduction strategy based on an anomaly detection confidence index to compress and calculate a load; the threat detection module is combined with an electric power knowledge graph to identify an attack mode and reversely trigger feature reconstruction; the model optimization module selects a Bayesian optimization, model distillation or federated learning local update strategy according to the data drift index and the resource state, and reduces the parameter adjustment amount; and the feedback enhancement module positions data defects through the misinformation knowledge graph and injects adversarial samples. According to the invention, each module significantly reduces resource consumption and response delay through the cooperation of data flow closed-loop linkage, feature compression, intelligent updating and data optimization.
Owner:HUANENG INFORMATION TECH CO LTD

Penetration testing method and system for mobile application of swan gap system

The invention relates to a penetration test method and system for mobile applications of a swan monk system, and the method comprises the steps: obtaining a current version installation package, extracting static asset data, and capturing dynamic behavior data; constructing a threat model for the gap distributed architecture; generating a penetration test case set through the threat model, and deploying and executing the penetration test case set; inputting the heterogeneous security telemetry data into the risk identification model, and executing a preset corresponding processing strategy; generating a penetration test report based on the risk judgment information and the execution result of the processing strategy; in conclusion, according to the penetration testing method and system for the mobile application of the swan-mong system, the threat model for the swan-mong distributed architecture is constructed, and the dynamic stain tracking and fuzzy testing technology is integrated, so that the cross-equipment safety risk is systematically detected; the method has the effects of effectively identifying the cross-equipment security threats in the swan-gap distributed architecture and improving the comprehensiveness and accuracy of the penetration test.
Owner:HONGMENG ECOLOGICAL SERVICES (SHENZHEN) CO LTD

System and method for monitoring threat detecting models

A system for monitoring threat models. The system stores test data that include activity data performed by two or more external sources. The test data includes data from at least one previous threat. The test data is updated with additional test data from at least one of two or more external sources. The additional test data includes new data associated with at least one new threat. The system receives two or more external sources from two or more threat models and implements them in a virtual test environment, which utilizes the two or more threat models to detect at least one previous threat and at least one new threat. When at least one of the two or more threat models does not detect the at least one new threat, an action is performed to modify it.
Owner:BANK OF AMERICA CORP

Heuristic recovery mechanism for malicious shortcut file parsing and threat detection

This invention presents a heuristic recovery mechanism for malicious shortcut file parsing and threat detection. It employs a resilience-oriented parsing engine, utilizes a dynamic byte ordering mechanism to adapt to underlying data, leverages a sliding window algorithm to accurately locate variable-length field terminators to extract hidden strings, and employs a recursive parsing strategy to deeply traverse undocumented nested structures and extension blocks. Parsing anomalies are treated as threat features and archived during the parsing process, and an iterative extraction strategy with adaptive parameters ensures full data acquisition. Based on the comprehensive parsing results, a three-dimensional threat model encompassing deception, evasion, and execution is constructed, achieving a deep mapping of malicious shortcut files from binary structure to logical behavior. This invention not only significantly improves the parsing success rate of variant samples but also effectively extracts fingerprint features from automatically generated samples, providing key technical support for modern shortcut-based attack and defense countermeasures.
Owner:NANKAI UNIV

Systems and methods for machine learning-based site-specific threat modeling and threat detection

Systems and methods for implementing a threat model that classifies contextual events as threats. The method can include: accessing a threat model; identifying a set of contextual events, wherein each contextual event comprises a set of semantic primitives predicted from a plurality of sensor streams; and determining a threat level for each contextual event based on threat probabilities.
Owner:AMBIENT AI INC

Information security and function security integrated risk assessment system and method

The invention relates to the technical field of risk assessment, and discloses an information security and function security integrated risk assessment system and method, which can integrate the cross influence between information security and function security and perform comprehensive risk assessment on the system. The system comprises a data acquisition module configured to obtain target data in a plurality of station subsystems, and a risk identification module configured to extract information security risk data by adopting an attack tree threat model, detect system vulnerabilities of the station subsystems according to the target data, obtain functional security risk data, and send the functional security risk data to the station subsystems. The risk assessment module is configured to optimize risk scores, obtain correlation between information security risk data and functional security risk data by adopting an Apriori algorithm, and predict risk changes by adopting an ARIMA model, the risk management module is configured to determine risk measures, and the risk reporting module is configured to generate a risk assessment report. The method has the characteristic of comprehensive and integrated risk assessment.
Owner:PIPECHINA SOUTH CHINA CO +1

Visual language model intelligent confrontation method based on multi-modal collaboration and related device

The invention discloses a visual language model intelligent confrontation method based on multi-modal collaboration and a related device. Inputting the rendered image rendered by the benign camouflage texture into the white-box visual language model, and maximizing the difference of different images to obtain a target antagonistic texture; inputting the adversarial image rendered by the benign text instruction and the target adversarial texture into a plurality of different visual language models to obtain a plurality of different suffixes, and screening out a target suffix which enables the total attack loss value of the plurality of visual language models to be minimum from the suffixes; inputting the target antagonistic texture and a target text instruction combined by the benign text instruction and the target suffix into a black box visual language model to obtain an error instruction; a composite threat model fusing physical deployability and digital high mobility is constructed, and a comprehensive safety test benchmark and a technical basis are provided for evaluating and improving the safety of an automatic driving visual language model.
Owner:SUN YAT SEN UNIV +1

Security zone isolation and dynamic expansion method and device for large-flow reliable transmission, equipment, storage medium and program product

The application relates to a security zone isolation and dynamic expansion method, device, equipment, storage medium and program product for large-flow reliable transmission. The method comprises the following steps: distributing a data block to be transmitted to an isolation device cluster, encrypting the data block by using an encryption algorithm, and establishing an encrypted channel for logical isolation; an adaptive sliding window algorithm is used to adjust the window size of flow monitoring, and a Bayesian threat model is used to generate flow anomaly results of each window size in the encrypted channel; the priority of the business to which the data block header belongs is analyzed, and the corresponding bandwidth guarantee weight is allocated to the data block according to the priority; the number of queries per second, the number of active sessions and the encryption calculation load of the business at the current time are extracted, and the preset weight coefficients are respectively given and summed to obtain a real-time resource demand value, and the expansion and contraction operation is performed on the calculation container carrying the business based on the real-time resource demand value. The method can improve the reliability of cross-security zone data transmission in the flow scene.
Owner:GUANGDONG ELECTRIC POWER COMM CO LTD

Monitoring device for security engineering

The invention discloses a monitoring device for security engineering. The monitoring device comprises a data acquisition module, a data processing and fusion module, a threat modeling module, a parameter optimization module and a strategy generation module. The invention relates to the technical field of security and protection equipment, and provides a monitoring device for security and protection engineering. The method has the technical effects that the consumption of storage bandwidth resources is remarkably reduced, the equipment overload risk is avoided, the target identification robustness under the interference of rain, fog, sand and dust is enhanced, the false alarm rate is reduced, and the cross-equipment collaborative response real-time performance and the cross-regional tracking efficiency are improved.
Owner:JIANGMEN POLYTECHNIC

Risk Evaluation and Threat Mitigation Using Artificial Intelligence

Systems and methods that create, use, enhance, maintain, and otherwise optimize a threat model—generally used for risk evaluation and threat mitigation—comprising artificial intelligence inherent in an entity is described. Certain embodiments describe, in countering a threat event, a need for an artificial intelligence entity to cooperate with non-expert users to give the users abilities to act on the domain in the users' self-interest. In countering a threat event, certain other embodiments describe that no single actor, in a heterogeneous collection of actors with varying abilities, may act in isolation to efficiently and effectively counter the threat to the collection; a minimum inevitable loss for the threat event may be achieved by an active cooperation of the heterogeneous actors of type comprising at least one of: expert users, non-expert users, and artificial intelligence entities that are sufficiently trained and knowledgeable on the threat event.
Owner:NESARIKAR ABHIJIT R +2

Security left shift research and development and operation method and device

The invention discloses a research, development and operation method and device for security left shift, and relates to the field of software development processes and security management.The method comprises the steps that a security demand baseline is established in the demand analysis stage, security demands and business demands are fused, and risk protection measures are determined; security architecture design review is carried out in the architecture design stage, and a security team carries out threat modeling on the system architecture and carries out one-ticket negative right; in the code development stage, code specifications, open source component vulnerabilities and logic risks are scanned in real time through a static code analysis tool, and a code security closed-loop management mechanism is established; in the compiling and constructing stage, code review and component list filing are implemented, a security review report is formed by combining a dynamic penetration test and a running flow test, and a security strategy is updated through a continuous monitoring mechanism to deal with new threats. Security practice can be systematically integrated in the early stage of the software development life cycle, and the later vulnerability repair cost is remarkably reduced.
Owner:CHINA CONSTR BANK CORP

Method for constructing sensitive information reverse reasoning threat model based on electricity price data

The invention provides a method for constructing a sensitive information reverse reasoning threat model based on electricity price data, and relates to the technical field of smart grid analysis. A homogeneous linear equation model between electricity price and an admittance matrix is constructed according to a direct current power flow model and a local marginal price theoretical model; the method comprises the following steps: extracting node and edge features from power data, inputting the features into a dynamic routing encoder, outputting encoding feature sequences of nodes and edges, carrying out time sequence modeling on encoding features, outputting power grid admittance parameter sequences at all moments, correcting and optimizing the parameter sequences, disturbing electricity price data by adopting a differential privacy mechanism, and outputting a power grid admittance parameter sequence. And in combination with the optimized parameter sequence, completing the construction of the sensitive information reverse reasoning threat model. According to the method, the dynamic feature coding and time sequence modeling technology is utilized, effective reverse inference of the power grid admittance parameters based on public data is achieved in combination with the differential privacy strategy, and privacy protection and risk assessment of electricity price data are completed in combination with the differential privacy strategy.
Owner:国网甘肃省电力公司陇南供电公司

Quantitative Analysis Method for the Four Core Capabilities of Cyber ​​Resilience

The present invention relates to the field of network resilience assessment technology, and specifically to a quantitative analysis method for the four core capabilities of network resilience, including: building a system to be analyzed, constructing a threat model and attacking the system to be analyzed, and then collecting the performance values ​​exhibited by each key function at each moment within a preset time period; summarizing the performance values ​​exhibited by a key function at each moment, and drawing a function change scatter plot, wherein the horizontal axis of the function change scatter plot is time and the vertical axis is the performance value exhibited by a key function; performing image analysis on the function change scatter plot to determine the resistance, recovery, perception and adaptability of the system to be analyzed. The present invention not only has the advantages of being objective, accurate and comparable, but can also analyze the network resilience capabilities exhibited by system functions in four stages when they are attacked, so as to facilitate a more in-depth analysis of the resilience capabilities of the system.
Owner:ZHENGZHOU UNIV +1

system

Provide a system. 【Solution means】 Means for connecting to an information network after obtaining user approval, Means for analyzing the text information obtained using natural language processing technology, Means for detecting inappropriate content including fraud, harassment, and illegal acts based on the analysis result, Means for generating and displaying warning information according to the detected inappropriate content, Means for temporarily stopping or blocking communication according to the severity of the inappropriate content, Means for learning a new threat model and updating the structure, Means for operating within a mobile device and notifying information warnings in real time, A system including the above.
Owner:SOFTBANK GROUP CORP

Application of security threat modeling and analysis methods, devices, equipment and media

The application relates to an application security threat modeling analysis method and device, equipment and medium, and belongs to the technical field of security modeling analysis. The method comprises the following steps: in response to a modeling analysis instruction of a target user, determining modeling selection information of the target user based on the modeling analysis instruction; determining a modeling analysis mode of the target user based on the modeling selection information; collecting modeling use data based on the modeling analysis mode, and generating modeling requirement information; performing key content analysis processing on the modeling requirement information to obtain modeling key data; obtaining a model page requirement of the target user; and creating an application security threat model based on the model page requirement and the modeling key data. The application has the effect of quickly and accurately analyzing security requirements according to actual business.
Owner:BILING (ZHUHAI HENGQIN) TECHNOLOGY CO LTD