Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

53 results about "Threat model" patented technology

Threat modeling is a process by which potential threats, such as structural vulnerabilities can be identified, enumerated, and prioritized – all from a hypothetical attacker’s point of view. The purpose of threat modeling is to provide defenders with a systematic analysis of the probable attacker’s profile, the most likely attack vectors, and the assets most desired by an attacker. Threat modeling answers questions like “Where are the high-value assets?”, “Where am I most vulnerable to attack?”, “What are the most relevant threats?”, and “Is there an attack vector that might go unnoticed?”.

Obstacle avoidance method of robot

The invention relates to the technical field of robot obstacle avoidance methods, in particular to an obstacle avoidance method of a robot. According to the method, a dynamic environment sensing system is constructed through multi-sensor fusion, and a dynamic feature description package and a static environment sketch are generated. The system generates a global navigation route by adopting an improved path planning algorithm, and constructs an obstacle space-time probability distribution map in combination with a multi-hypothesis prediction technology. According to the method, a two-channel intention analysis mechanism is introduced, the motion intention of a target is predicted by analyzing the kinematics characteristics and the biological behavior characteristics of the target, and a four-dimensional space-time threat model is established by fusing a space-time probability graph. And according to the threat level, a hierarchical obstacle avoidance strategy is dynamically generated, wherein the hierarchical obstacle avoidance strategy comprises various response modes such as path fine adjustment, speed cooperative adjustment and emergency channel avoidance. The environment cognition and behavior model is continuously updated through a closed-loop optimization mechanism, and finally safe and smooth autonomous navigation in the high-dynamic man-machine coexistence environment is achieved.
Owner:HUBEI BUSINESS COLLEGE

Client identity authentication security evaluation method and system combined with adversarial sample simulation

The invention provides a client identity authentication security evaluation method and system combined with adversarial sample simulation, and relates to the technical field of information security. According to the invention, end-cloud integrated evaluation is carried out under a white-box and black-box threat model for multi-mode identification objects of human face, voiceprint, fingerprint and behavior characteristics. The method comprises the steps of establishing reference performance through legal samples, generating transferable adversarial input, performing secure injection on a communication layer, calculating a robustness index, performing adaptive optimization, performing differential evaluation on protection effectiveness under protection configuration starting and non-starting, and performing risk grading and reinforcement according to a result. And finally, outputting a reproducible security and compliance conclusion through differential privacy and federal evaluation.
Owner:CHENGDU CHUANGXIN HUATONG INFORMATION TECH CO LTD

Threat model assistant for software development

The present disclosure of the various embodiments relates to using a large language model to assistant with the creation of secure code and / or the completion of threat modeling tasks in software development. In one example, a system comprises a computing device configure to identify a prompt that requests generating secure source code for source code with a security vulnerability. A security data source is queried for a security threat embedding. The security threat embedding is received from the security data source and an augmented prompt is generated. The augmented prompt is transmitted to the large language model. A secure source code is received from the large language model and imported into application source code in a software development environment.
Owner:AMERICAN EXPRESS TRAVEL RELATED SERVICES CO INC

Threat modeling using machine learning and context information

Various example embodiments provide for threat modeling using machine learning models and context information, where a threat model is generated based on a threat model diagram for a target system being analyzed for threat risks / scenarios. For an individual threat model generated, a threat scenario (e.g., each individual threat scenario) described in the individual threat model can be processed (e.g., individually processed) by a plurality of machine learning models to determine a set of generic mitigation labels for the threat scenario, where each generic mitigation label corresponds to a generic mitigation strategy for mitigating the threat scenario. The set of generic mitigation labels for the threat scenario with context information can be processed by one or more large language models to generate a set of specific mitigation labels for the individual threat model, where each specific mitigation label corresponds to a specific mitigation strategy.
Owner:SNOWFLAKE INC

Multi-identity security verification system based on big data

The invention relates to the technical field of identity security verification, and discloses a multi-identity security verification system based on big data. The system comprises a verification collection module, a feature construction module, a risk modeling module and a decision engine module, wherein the verification collection module obtains user multi-source biological features, behavior tracks and equipment environment data, and performs preprocessing to generate an initial feature set; the feature construction module extracts spatiotemporal behavior patterns and cross-device association features and fuses the spatiotemporal behavior patterns and the cross-device association features into a multi-dimensional The risk modeling module loads a pre-trained dynamic threat model, carries out real-time risk layering on the multi-dimensional feature matrix, and outputs a risk level identifier and an abnormal feature vector; and the decision engine module calls a corresponding verification strategy library, and generates a multi-factor verification instruction set in combination with the abnormal feature vector. The system realizes comprehensive verification of user identities through multi-source data integration, dynamic risk assessment and precise strategy matching, and adapts to various high-security demand scenes.
Owner:SHENZHEN ZHICHUANG JIACHENG TECH CO LTD

Methods for Constructing Threat Models Based on Sensitive Information from Electricity Price Data

This invention provides a method for constructing a threat model based on sensitive information reverse inference using electricity price data, belonging to the field of smart grid analysis technology. This invention constructs a homogeneous linear equation model between electricity price and admittance matrix based on a DC power flow model and a local marginal price theory model. It extracts node and edge features from power data, inputs them into a dynamic routing encoder, outputs encoded feature sequences of nodes and edges, performs time-series modeling on the encoded features, outputs the grid admittance parameter sequence at each time step, and corrects and optimizes the parameter sequence. A differential privacy mechanism is used to perturb the electricity price data. Combined with the optimized parameter sequence, the sensitive information reverse inference threat model is constructed. This invention utilizes dynamic feature encoding and time-series modeling techniques, combined with a differential privacy strategy, to achieve effective reverse inference of grid admittance parameters based on publicly available data, and also completes privacy protection and risk assessment of electricity price data using the differential privacy strategy.
Owner:国网甘肃省电力公司陇南供电公司

Security threat model optimization system and method based on online self-learning

The invention relates to the technical field of data processing, in particular to a security threat model optimization system and method based on online self-learning, and the system comprises a data collection module which eliminates the electromagnetic interference of a power grid, dynamically adjusts the sampling frequency, and improves the data quality; the feature processing module extracts statistical features and topological features by adopting a dual-channel parallel architecture, and dynamically selects a dimension reduction strategy based on an anomaly detection confidence index to compress and calculate a load; the threat detection module is combined with an electric power knowledge graph to identify an attack mode and reversely trigger feature reconstruction; the model optimization module selects a Bayesian optimization, model distillation or federated learning local update strategy according to the data drift index and the resource state, and reduces the parameter adjustment amount; and the feedback enhancement module positions data defects through the misinformation knowledge graph and injects adversarial samples. According to the invention, each module significantly reduces resource consumption and response delay through the cooperation of data flow closed-loop linkage, feature compression, intelligent updating and data optimization.
Owner:HUANENG INFORMATION TECH CO LTD

Penetration testing method and system for mobile application of swan gap system

The invention relates to a penetration test method and system for mobile applications of a swan monk system, and the method comprises the steps: obtaining a current version installation package, extracting static asset data, and capturing dynamic behavior data; constructing a threat model for the gap distributed architecture; generating a penetration test case set through the threat model, and deploying and executing the penetration test case set; inputting the heterogeneous security telemetry data into the risk identification model, and executing a preset corresponding processing strategy; generating a penetration test report based on the risk judgment information and the execution result of the processing strategy; in conclusion, according to the penetration testing method and system for the mobile application of the swan-mong system, the threat model for the swan-mong distributed architecture is constructed, and the dynamic stain tracking and fuzzy testing technology is integrated, so that the cross-equipment safety risk is systematically detected; the method has the effects of effectively identifying the cross-equipment security threats in the swan-gap distributed architecture and improving the comprehensiveness and accuracy of the penetration test.
Owner:HONGMENG ECOLOGICAL SERVICES (SHENZHEN) CO LTD

Heuristic recovery mechanism for malicious shortcut file parsing and threat detection

This invention presents a heuristic recovery mechanism for malicious shortcut file parsing and threat detection. It employs a resilience-oriented parsing engine, utilizes a dynamic byte ordering mechanism to adapt to underlying data, leverages a sliding window algorithm to accurately locate variable-length field terminators to extract hidden strings, and employs a recursive parsing strategy to deeply traverse undocumented nested structures and extension blocks. Parsing anomalies are treated as threat features and archived during the parsing process, and an iterative extraction strategy with adaptive parameters ensures full data acquisition. Based on the comprehensive parsing results, a three-dimensional threat model encompassing deception, evasion, and execution is constructed, achieving a deep mapping of malicious shortcut files from binary structure to logical behavior. This invention not only significantly improves the parsing success rate of variant samples but also effectively extracts fingerprint features from automatically generated samples, providing key technical support for modern shortcut-based attack and defense countermeasures.
Owner:NANKAI UNIV

Visual language model intelligent confrontation method based on multi-modal collaboration and related device

The invention discloses a visual language model intelligent confrontation method based on multi-modal collaboration and a related device. Inputting the rendered image rendered by the benign camouflage texture into the white-box visual language model, and maximizing the difference of different images to obtain a target antagonistic texture; inputting the adversarial image rendered by the benign text instruction and the target adversarial texture into a plurality of different visual language models to obtain a plurality of different suffixes, and screening out a target suffix which enables the total attack loss value of the plurality of visual language models to be minimum from the suffixes; inputting the target antagonistic texture and a target text instruction combined by the benign text instruction and the target suffix into a black box visual language model to obtain an error instruction; a composite threat model fusing physical deployability and digital high mobility is constructed, and a comprehensive safety test benchmark and a technical basis are provided for evaluating and improving the safety of an automatic driving visual language model.
Owner:SUN YAT SEN UNIV +1

Security zone isolation and dynamic expansion method and device for large-flow reliable transmission, equipment, storage medium and program product

The application relates to a security zone isolation and dynamic expansion method, device, equipment, storage medium and program product for large-flow reliable transmission. The method comprises the following steps: distributing a data block to be transmitted to an isolation device cluster, encrypting the data block by using an encryption algorithm, and establishing an encrypted channel for logical isolation; an adaptive sliding window algorithm is used to adjust the window size of flow monitoring, and a Bayesian threat model is used to generate flow anomaly results of each window size in the encrypted channel; the priority of the business to which the data block header belongs is analyzed, and the corresponding bandwidth guarantee weight is allocated to the data block according to the priority; the number of queries per second, the number of active sessions and the encryption calculation load of the business at the current time are extracted, and the preset weight coefficients are respectively given and summed to obtain a real-time resource demand value, and the expansion and contraction operation is performed on the calculation container carrying the business based on the real-time resource demand value. The method can improve the reliability of cross-security zone data transmission in the flow scene.
Owner:GUANGDONG ELECTRIC POWER COMM CO LTD

Monitoring device for security engineering

The invention discloses a monitoring device for security engineering. The monitoring device comprises a data acquisition module, a data processing and fusion module, a threat modeling module, a parameter optimization module and a strategy generation module. The invention relates to the technical field of security and protection equipment, and provides a monitoring device for security and protection engineering. The method has the technical effects that the consumption of storage bandwidth resources is remarkably reduced, the equipment overload risk is avoided, the target identification robustness under the interference of rain, fog, sand and dust is enhanced, the false alarm rate is reduced, and the cross-equipment collaborative response real-time performance and the cross-regional tracking efficiency are improved.
Owner:JIANGMEN POLYTECHNIC

Risk Evaluation and Threat Mitigation Using Artificial Intelligence

Systems and methods that create, use, enhance, maintain, and otherwise optimize a threat model—generally used for risk evaluation and threat mitigation—comprising artificial intelligence inherent in an entity is described. Certain embodiments describe, in countering a threat event, a need for an artificial intelligence entity to cooperate with non-expert users to give the users abilities to act on the domain in the users' self-interest. In countering a threat event, certain other embodiments describe that no single actor, in a heterogeneous collection of actors with varying abilities, may act in isolation to efficiently and effectively counter the threat to the collection; a minimum inevitable loss for the threat event may be achieved by an active cooperation of the heterogeneous actors of type comprising at least one of: expert users, non-expert users, and artificial intelligence entities that are sufficiently trained and knowledgeable on the threat event.
Owner:NESARIKAR ABHIJIT R +2

Security left shift research and development and operation method and device

The invention discloses a research, development and operation method and device for security left shift, and relates to the field of software development processes and security management.The method comprises the steps that a security demand baseline is established in the demand analysis stage, security demands and business demands are fused, and risk protection measures are determined; security architecture design review is carried out in the architecture design stage, and a security team carries out threat modeling on the system architecture and carries out one-ticket negative right; in the code development stage, code specifications, open source component vulnerabilities and logic risks are scanned in real time through a static code analysis tool, and a code security closed-loop management mechanism is established; in the compiling and constructing stage, code review and component list filing are implemented, a security review report is formed by combining a dynamic penetration test and a running flow test, and a security strategy is updated through a continuous monitoring mechanism to deal with new threats. Security practice can be systematically integrated in the early stage of the software development life cycle, and the later vulnerability repair cost is remarkably reduced.
Owner:CHINA CONSTR BANK CORP

Method for constructing sensitive information reverse reasoning threat model based on electricity price data

The invention provides a method for constructing a sensitive information reverse reasoning threat model based on electricity price data, and relates to the technical field of smart grid analysis. A homogeneous linear equation model between electricity price and an admittance matrix is constructed according to a direct current power flow model and a local marginal price theoretical model; the method comprises the following steps: extracting node and edge features from power data, inputting the features into a dynamic routing encoder, outputting encoding feature sequences of nodes and edges, carrying out time sequence modeling on encoding features, outputting power grid admittance parameter sequences at all moments, correcting and optimizing the parameter sequences, disturbing electricity price data by adopting a differential privacy mechanism, and outputting a power grid admittance parameter sequence. And in combination with the optimized parameter sequence, completing the construction of the sensitive information reverse reasoning threat model. According to the method, the dynamic feature coding and time sequence modeling technology is utilized, effective reverse inference of the power grid admittance parameters based on public data is achieved in combination with the differential privacy strategy, and privacy protection and risk assessment of electricity price data are completed in combination with the differential privacy strategy.
Owner:国网甘肃省电力公司陇南供电公司

system

Provide a system. 【Solution means】 Means for connecting to an information network after obtaining user approval, Means for analyzing the text information obtained using natural language processing technology, Means for detecting inappropriate content including fraud, harassment, and illegal acts based on the analysis result, Means for generating and displaying warning information according to the detected inappropriate content, Means for temporarily stopping or blocking communication according to the severity of the inappropriate content, Means for learning a new threat model and updating the structure, Means for operating within a mobile device and notifying information warnings in real time, A system including the above.
Owner:SOFTBANK GROUP CORP

Application of security threat modeling and analysis methods, devices, equipment and media

The application relates to an application security threat modeling analysis method and device, equipment and medium, and belongs to the technical field of security modeling analysis. The method comprises the following steps: in response to a modeling analysis instruction of a target user, determining modeling selection information of the target user based on the modeling analysis instruction; determining a modeling analysis mode of the target user based on the modeling selection information; collecting modeling use data based on the modeling analysis mode, and generating modeling requirement information; performing key content analysis processing on the modeling requirement information to obtain modeling key data; obtaining a model page requirement of the target user; and creating an application security threat model based on the model page requirement and the modeling key data. The application has the effect of quickly and accurately analyzing security requirements according to actual business.
Owner:BILING (ZHUHAI HENGQIN) TECHNOLOGY CO LTD

System and method for enabling automated threat model assessment

Computing platforms, methods, and storage media for enabling automated threat model assessment for a software solution are disclosed. Exemplary implementations may: obtain software architecture data from a software design tool, the software architecture data associated with design and deployment of the software solution; create, based on the obtained software architecture data, integration data comprising a subset of the software architecture data that is relevant to threat modeling, the integration data formatted for import by a threat assessment tool as threat assessment input data; and provide, to the threat assessment tool, access to the integration data for use in automated threat assessment, reducing time and effort in processing. Exemplary implementations may provide, as an input to a large language model (LLM), a data mapping of stored mapping relationships between software architecture data objects and threat assessment data objects; and obtain, as an output of the large language model, the translation blueprint.
Owner:THE TORONTO DOMINION BANK

An unmanned aerial vehicle path planning method based on improved firefly algorithm

ActiveCN116700329BSimulationUncrewed vehicle
This invention discloses a UAV trajectory planning method based on an improved firefly algorithm, comprising the following steps: S1, constructing an environment model and a threat model for UAV trajectory planning; S2, setting constraints and an objective function for UAV trajectory planning based on the environment model and the threat model; S3, optimizing the objective function using the improved firefly algorithm to obtain the UAV trajectory route. This invention models the environment of the UAV trajectory planning scenario, analyzes the static domain dynamic threat costs that the UAV may face, and then analyzes the remaining constraints and objective function. It optimizes the objective function using an improved firefly algorithm, adaptively adjusting the light intensity absorption coefficient and firefly position update of the firefly algorithm, and introducing a perturbation mechanism to expand the algorithm's search space, improving the global search capability and convergence efficiency of the firefly algorithm, and ensuring better global optimality of the generated path.
Owner:UNIV OF ELECTRONICS SCI & TECH OF CHINA +1

Generating threat statements for a threat model using artificial intelligence

Methods and systems are described herein for a threat modeling system. The threat modeling system may use machine learning and operator help to determine whether the threat model has errors and / or whether the threat model is complete. In particular, the threat modeling system may input each threat or threat statement within the threat model into a machine learning model that has been trained to detect errors within the threat model. When errors are detected, the threat modeling system may present those errors to an operator to be fixed. In addition, the threat modeling system may enable an operator to add new threats to the model and then check those threats for error and completeness.
Owner:CAPITAL ONE SERVICES LLC

An unmanned aerial vehicle countermeasure plan generation method based on artificial intelligence technology

The application relates to the technical field of data analysis, in particular to a UAV countermeasure plan generation method based on artificial intelligence technology, which comprises the following steps: a database with multiple countermeasure success cases is established; a UAV threat model is established; the threat model is coupled with a current use environment to obtain a coupling model; the matching degree of countermeasures is calculated; an artificial intelligence module is used to train the threat model and the coupling model according to the multiple countermeasure success cases; according to the determined threat model, coupling model and matching degree of UAV behavior countermeasures, the highest corresponding countermeasures are selected and output; the model focuses on the key features of speed, acceleration, mass and external load, the generation time of the plan is shortened, and the response speed is improved; through subsequent environment coupling, the subsequent strategy can be adjusted according to the specific environment; the unit cost, response time and adaptation rate of the countermeasures are calculated, and the optimal allocation of resources is realized.
Owner:FUJIAN LINGXIN INFORMATION TECH CO LTD

Cross-domain anti-threat system, method and device, electronic equipment and storage medium

The invention provides a cross-domain anti-threat system, method and device, electronic equipment and a storage medium, the system comprises a server and at least two model participants, the server comprises a federated learning and calculation module, and each model participant comprises a training module and an encryption module; the federal learning and calculation module sends the initial anti-threat model to the training module; after the training module trains the initial anti-threat model, the parameter increment and / or gradient of the initial anti-threat model are / is sent to the encryption module; the encryption module encrypts the data and sends the encrypted data to the federal learning and calculation module; the federated learning and calculation module receives encryption parameter increments and / or gradients of all model participants, cross-domain global parameters and / or gradients are obtained through aggregation of a security calculation technology, and a global anti-threat model is generated according to the cross-domain global parameters and / or gradients and distributed to all the model participants; and a model participant receives the global anti-threat model, analyzes real-time user behavior data based on the global anti-threat model, and triggers an early warning mechanism when determining that a suspicious user behavior exists.
Owner:CHINA MOBILE COMM LTD RES INST +1

Multi-stage power supply recovery method for power distribution system containing reconfigurable soft switch to cope with network-physical collaborative threat

The invention discloses a multi-stage power supply recovery method for a power distribution system containing a reconfigurable soft switch to cope with a network-physical collaborative threat, and the method comprises the steps: 1, building a network-physical collaborative threat model, so as to analyze the influence characteristics of the network-physical collaborative threat model on the power distribution system; 2, establishing a reconfigurable soft switch mathematical model; 3, establishing a multi-stage power supply recovery model of the power distribution system containing the reconfigurable soft switch under the network-physical collaborative threat; and 4, converting the multi-stage power supply recovery model of the power distribution system containing the reconfigurable soft switch under the network-physical cooperative threat into a mixed integer second-order cone programming constraint, and then performing solution to obtain a power distribution system operation scheme containing reconfigurable soft switch action and a remote controllable switch. According to the invention, the operation of the remote controllable switch and the reconfigurable soft switch is coordinated, so that the flexible regulation and control capability and the load recovery level of the system under extreme conditions can be improved.
Owner:HEFEI UNIV OF TECH

A system and method for ai impact assessment with threat modelling for responsible ai requirements

PCT designated stageWO2026133070A1Platform integrity maintainanceMachine learningData protection impact assessmentBusiness requirements
A system (120) and method (400) for artificial intelligence impact assessment with threat modelling for responsible artificial intelligence requirements is disclosed. The system (120) comprises a business requirement module (315) for capturing objectives, a responsible artificial intelligence threat modelling module (320) for identifying risks, and a compliance module (325) for generating questionnaires and initiating data protection impact assessments. An automatic regulatory requirement module (330) maps risk to global Al regulations, while a technical safeguard recommendation module (335) provides dynamic mitigation strategies and session summaries. A human-in-the-loop module (340) enables expert validation, and a workflow orchestration module (350) structures collaborative reviews. A permission workflow module (345) assigns risk scores and authorizes deployment. A dashboard module (355) offers real-time monitoring of assessments, compliance status, approvals, and risk metrics, ensuring accelerated, accurate, and safe Al impact assessment aligned with responsible Al principles.
Owner:PRIVASAPIEN TECH PTE LTD

A method for security isolation and threat detection of virtualized network slices

The application belongs to the technical field of network security, and specifically relates to a security isolation and threat detection method for a virtualized network slice, specific steps of the security isolation and threat detection method being as follows: virtualized network slice threat model construction, dynamic security isolation algorithm based on zero trust, deep reinforcement learning threat detection model design, and isolation strategy and detection result self-adaptive linkage mechanism; existing schemes mostly adopt static weights or binary judgments, a multi-time scale dynamic trust decay model is constructed in this paper, and three evaluations of historical behavior, real-time behavior and environmental context are fused; existing schemes only realize two-layer linkage of detection and response, three-layer intelligent linkage of detection, evaluation and execution is designed in this paper, and a closed-loop optimization from threat awareness to protection strategy is established; existing schemes rely on traditional machine learning or single-agent reinforcement learning, a multi-agent cooperation architecture is adopted in this paper, and complex threat detection accuracy is significantly improved through information sharing and collaborative decision-making.
Owner:HUNAN UNIV OF SCI & ENG

System and method for defending against cybersecurity attacks

A computer-implemented method and system for weighing and prioritizing cybersecurity attacks are disclosed. The method includes obtaining data regarding one or more cyber-attacks, generating nodes representing the attacks, calculating edge weights between adjacent nodes using a custom risk function, and outputting a weighted attack graph. Each node is defined by attributes including severity, likelihood, protection level, and layer in a threat model. Edges between nodes are assigned weights that quantify risk based on severity, likelihood of success, and system protection. The resulting weighted attack graph provides an interactive visual representation of potential attack paths, enabling cybersecurity professionals to allocate defensive resources more efficiently and respond to critical threats.
Owner:HIGMAN MILES

Live threat modeling framework

An example computer system for live threat modeling for an enterprise can include: one or more processors; and non-transitory computer-readable storage media encoding instructions which, when executed by the one or more processors, causes the computer system to: prepare abstracts for applications associated with the enterprise to form a threat model; monitor development phases of the applications; and apply the threat model to the applications during each of the development phases to identify risk.
Owner:WELLS FARGO BANK NA

Block chain privacy protection query method based on distributed point function

The invention discloses a block chain privacy protection query method based on a distributed point function. The block chain privacy protection query method comprises the following steps: completing system participant definition, threat model setting and preprocessing work of a consensus node end; generating a query request through a distributed point function (DPF) and distributing the query request; performing share evaluation, multi-block processing and parallel optimization; and obtaining and verifying a final result. According to the method, a privacy query mechanism and a garrison mechanism based on the distributed point function are introduced, so that the privacy protection capability on query keywords in a blockchain light node outsourcing query scene is remarkably improved, and the correctness and credibility of a query result are effectively guaranteed in an untrusted full-node environment. According to the method, the computing and communication burden is obviously reduced while privacy protection is achieved, the trust premise can be met only by deploying Intel SGX in a small number of all nodes, and the trusted hardware deployment threshold is obviously reduced.
Owner:CHANGAN UNIV

A dynamic embedded system network security scene modeling and threat analysis method and system

The application discloses a kind of dynamic embedded system network security scene modeling and threat analysis method and system, including the following steps: scene construction, for constructing scene graph data;Dynamic simulation, for visual presentation to scene model;Automatic threat identification, for constructing attack path or threat correlation diagram;Threat intelligence correlation, for matching threat item with vulnerability intelligence data;Risk rating and model improvement, for improving scene model;Threat model visualization, for superimposed visualization display of threat analysis result;Report generation and export, for automatically generating and exporting security analysis report;Model management, for centralized storage and collaborative management.The application realizes full-dimensional threat identification to embedded system software, network, hardware and physical attack, greatly improves the comprehensiveness, accuracy and analysis efficiency of threat analysis, effectively solves the problem that traditional method is not fully covered, high artificial dependence, risk assessment is not accurate.
Owner:COMP APPL RES INST CHINA ACAD OF ENG PHYSICS