Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

68 results about "Threat perception" patented technology

Threat perception is defined as a deep sense of vulnerability that is assumed to be negative, likely to result in loss, and largely out of one's control (Dutton & Jackson, 1987; Jackson & Dutton, 1988) -- Glibert, 2005, 742. Threat perception is commonly viewed as a requirement to change organizational inertia.

Dynamic honey point collaborative intelligent threat trapping system and method based on genetic algorithm

The invention discloses a dynamic honey point collaborative intelligent threat trapping system and method based on a genetic algorithm in the technical field of network security, and the system comprises a multi-source information collection and dual-mode output module, a reinforcement learning strategy engine, a graph neural network prediction module, a digital twin simulation environment, a strategy verification and optimization module, and a real network defense execution module. A dynamic honey point deployment strategy is generated in real time through a reinforcement learning strategy engine, and the problem of strategy stiffness is solved; a third-generation non-dominated sorting genetic algorithm (NSGA-III) multi-objective optimization algorithm is used for coordinating honey point density adjustment, trip line sensitivity calibration and other actions; attacking path risks are quantified based on a threat scoring formula, digital twin environment pre-verification and high-risk node precise protection are driven, closed-loop linkage of threat perception, strategy optimization and active trapping is finally achieved, and the intelligent defense capability capable of achieving autonomous evolution is formed.
Owner:积至(海南)信息技术有限公司

Multi-modal threat sensing method and system based on space-time diagram neural network

The invention relates to the technical field of multi-modal data processing, and discloses a multi-modal threat perception method and system based on a space-time diagram neural network, and the method comprises the steps: obtaining a multi-modal original data set in a vehicle insurance claim settlement link, and carrying out the business relation mining and space-time dynamic analysis, and obtaining an entity space-time relation diagram; inputting the entity space-time relation graph into a space-time graph neural network for space-time fusion to obtain a node threat embedding vector; performing graph contrast learning and cross-modal feature discrimination on the node threat embedding vector to obtain a vehicle insurance threat feature vector; and carrying out fraud space-time propagation modeling based on the vehicle insurance threat feature vector, and generating a vehicle insurance threat blocking strategy, the method can accurately predict a propagation path and an influence boundary of gang fraud in a vehicle insurance ecological network, and identifies potential threats and starts prevention measures before a fraud behavior is completely displayed.
Owner:GUANGDONG ICAR GUARD INFORMATION TECH

Data security processing method and system based on distributed storage

The invention relates to a data security processing method and system based on distributed storage, and relates to the technical field of computer information processing. The method comprises the following steps: cutting data into encryption fragments with a configurable number by adopting a dynamic fragmentation strategy, and generating a physically isolated dynamic check block in combination with a timestamp to realize tampering prevention; a dynamic threshold value is dynamically calculated based on the data sensitivity index and the node load, and the node is optimized through the reliability score for cooperative decryption; a database table is divided into independent marshalling storage according to main foreign key association, foreign key fields are encrypted by adopting cross keys, and cross-marshalling access needs to meet a multi-key threshold condition; an intelligent threat perception engine is constructed, access logs and threat intelligence are analyzed in real time, and key rotation, fragment replacement and joint defense response mechanisms are dynamically triggered. According to the invention, full life cycle protection of data is realized, and the problems of key leakage risk and cross-table association attack are effectively solved.
Owner:WUHAN ANYU INFORMATION SECURITY TECH CO LTD

Pilot dynamic evaluation method, system and equipment based on TEM model and storage medium

The invention relates to the technical field of TEM models, provides a pilot dynamic evaluation method, system and device based on a TEM model and a storage medium, and solves the problems of low accuracy of flight training evaluation and poor adaptability of a training scheme. The method comprises the steps that flight control, physiological monitoring and cockpit voice data are acquired, and a multi-modal data stream is formed through time synchronization; performing threat perception, error management and non-technical skill three-level evaluation on the feature vector by using a TEM model, generating corresponding indexes, and fusing the indexes into a comprehensive feature vector; respectively processing the time sequence and cognitive features by means of a dual-channel long-short-term memory network, and extracting deep features; performing decision tracing by adopting an SHAP value so as to locate a capability defect node; finally, defect types are matched through a personalized improvement scheme recommendation mechanism, and self-adaptive training content is generated. According to the invention, the accuracy of flight training evaluation and the adaptability of the training scheme are improved.
Owner:CHINA SOUTHERN TECHNOLOGY (GUANGDONG HENGQIN) CO LTD +2

Security defense strategy method and system based on AI Agent dynamic optimization

The invention provides a method and a system for dynamically optimizing a security defense strategy based on an AI Agent, and aims to solve the problems that the traditional network security defense strategy is static and cannot adapt to a dynamic network environment and novel network threats, and the processing efficiency of massive security data is low and the response is not timely. The method comprises the following steps: firstly, realizing whole network node data acquisition through a distributed AI Agent, performing accurate identification in combination with a multi-dimensional threat perception and fusion detection mechanism, and establishing a threat parameter quantitative evaluation model; secondly, the AI Agent generates a dynamic defense strategy according to the analysis result of the intelligent threat detection and the real-time state of the network in combination with threat features and risk assessment; and finally, according to the dynamic defense response result, realizing attack path tracking, accurate vulnerability positioning, automatic repair execution and traceability information retention processing. According to the method, real-time sensing and quick response to network threats can be realized, and the hysteresis of a traditional static defense strategy is overcome.
Owner:ZHEJIANG SHUREN UNIV

Vehicle-mounted network security threat sensing system and method based on edge and cloud collaboration

The invention provides a vehicle-mounted network security threat sensing system and method based on edge and cloud collaboration, and belongs to the technical field of vehicle network security. Comprising the following steps: S1, collecting vehicle multi-modal data through an edge layer; s2, preprocessing the multi-modal data of the vehicle; s3, performing feature extraction on the preprocessed vehicle multi-modal data to obtain a high-dimensional feature vector; s4, calculating a threat confidence score based on the high-dimensional feature vector; s5, performing hierarchical response decision based on the threat confidence score and a predefined response strategy library, and generating hierarchical response data; s6, extracting threat metadata based on the hierarchical response data; s7, performing global association analysis based on the threat metadata, and upgrading a defense system; and S8, based on the global threat intelligence and the upgraded defense system, carrying out edge layer updating, and then skipping to S1. The method is beneficial to eliminating response delay, relieving network bandwidth pressure and optimizing cloud computing resource load.
Owner:上海星宇智行技术有限公司

Road toll collection system network security task dynamic allocation and load balancing method

The invention belongs to the technical field of network management, and particularly relates to a road toll collection system network security task dynamic allocation and load balancing method, which comprises a road toll collection system, and the road toll collection system comprises a network security task dynamic allocation system and a load balancing system. The network security task dynamic allocation system serves as an intelligent security protection scheduling center, is used for coping with continuous evolution threats, and comprises a real-time threat perception and response scheduling integration, a resource elastic scaling system and a strategy self-adaptive adjustment system. The load balancing system serves as a foundation stone of service continuity and performance, ensures stable operation of high-concurrency transactions, and comprises an intelligent flow distribution system, an automatic fault isolation and recovery system and a load balancing system. The method can deal with sudden security events, optimize the resource utilization rate, improve the protection precision, guarantee high availability, improve the user experience and support the elastic expansion of the system.
Owner:EAST CHINA JIAOTONG UNIVERSITY

Public network-oriented global threat perception method and system

The invention provides a public network-oriented global threat perception method and system, and relates to the technical field of advanced persistent attack threat detection, and the specific technical scheme is as follows: setting a network trip line and a domain name trip line of a public network to establish honey point equipment, and establishing honey court equipment based on an IP address reputation mechanism; building a honey hole device based on a camouflage traceability technology and a reverse chain technology, and building a sub-honey array based on a honey point device, a honey court device and the honey hole device; generating a honey point template based on the sub-honey array to deploy honey point equipment, obtaining public network traffic based on a honey yard equipment preposition and combining with the honey point equipment, and detecting the public network traffic to obtain a detection result; and making a countering strategy of the honey hole device based on the behavior of the attacker in the detection result, obtaining threat intelligence of the attacker, and updating IP address resources of the honey point device and the honey court device based on the threat intelligence. According to the invention, a low-intrusive threat probing mechanism and a high-universality global threat sensing system are established through four-honey equipment.
Owner:GUANGZHOU UNIVERSITY

Network situation intelligent perception security system based on multi-source data analysis

The invention relates to the technical field of network situation awareness, in particular to a network situation intelligent awareness security system based on multi-source data analysis, which accurately acquires a perception threat confidence vector, a service interruption risk vector, an attack chain complete vector and a user behavior deviation vector based on multi-source data fusion and targeted analysis. According to the method, network situation key information can be comprehensively and accurately captured, a reliable basis is provided for subsequent decision making, the comprehensiveness and real-time performance of threat perception are improved, dynamic balance of safety protection, service efficiency and operation and maintenance cost is achieved by relying on a multi-target game mechanism and a network space digital twinning technology, and the safety and reliability of threat perception are improved. A simulation deduction deviation value is introduced as a core index of strategy evaluation, a real network situation is simulated through a digital twin environment, the difference between a strategy execution effect and an expected target is quantified, and in combination with reproduction of an attack scene by the twin environment, deviation value analysis is ensured to be more fit with the real network environment.
Owner:GUANGZHOU YEDUN INFORMATION TECHNOLOGY CO LTD +1

Big data risk early warning and evaluation method based on artificial intelligence

The invention relates to the field of internet security, and discloses a big data risk early warning and evaluation method based on artificial intelligence, comprising the following steps: step S1, collecting original security data from a heterogeneous data source; s2, constructing a global causal model; s3, constructing and evolving an event causal evolution diagram so as to establish directed edges with weights among the nodes; s4, dynamically evaluating the ability level of the attacker; s5, performing adversarial intention projection; s6, calculating a dynamic risk score; and generating an early warning when the score exceeds an early warning threshold. According to the method, asymmetric information flows among event types are quantified through transfer entropy, and a context evidence fusion mechanism is combined, so that a real causal relationship and a simple statistical correlation can be distinguished; the defect that a high false alarm rate is easily generated based on rule or simple threshold matching is overcome, so that the event causal evolution diagram can accurately reflect the internal logic and time sequence characteristics of an attack behavior, and the accuracy of complex threat perception is improved.
Owner:ZHEJIANG UNIV OF SCI & TECH

Network security threat perception and adaptive defense system based on artificial intelligence

The invention belongs to the technical field of network security management and control, and particularly relates to a network security threat perception and adaptive defense system based on artificial intelligence. Comprising a data acquisition preprocessing module, a threat feature intelligent mining module, a threat situation comprehensive evaluation module, a self-adaptive defense strategy generation module, a defense effect dynamic feedback module and a background supervision terminal. The data acquisition and preprocessing module acquires various data from a network environment and performs related preprocessing operation, the threat feature intelligent mining module mines potential network security threat features, and the threat situation comprehensive evaluation module comprehensively evaluates the network security threat situation. The self-adaptive defense strategy generation module generates a self-adaptive defense strategy based on the threat level and the influence range, and the defense effect dynamic feedback module monitors and evaluates the implementation effect of the self-adaptive defense strategy in real time, thereby providing an omnibearing, intelligent and self-adaptive guarantee for network security.
Owner:YALONG RIVER HYDROPOWER DEV CO LTD

Power grid vulnerability micropatch generation method, system and device based on call chain backtracking and medium

The invention discloses a power grid vulnerability micropatch generation method, system and device based on call chain backtracking and a medium, and belongs to the technical field of network security, and the method comprises the following steps: based on a dynamic probe, realizing kernel layer protocol analysis, lock-free acquisition of system call and user state call chain reconstruction; key path marking is realized through LLVM-IR semantic analysis and power business feature matching; generating a security micropatch based on the metadata and realizing isolated hot loading; and the patch compatibility is ensured by adopting digital simulation verification and a layered release mechanism. The method has the advantages that a five-dimensional cooperative power grid active defense system of observation-modeling-reasoning-evaluation-arrangement is constructed, millisecond observation is achieved through eBPF collection synchronized with PTP, a multi-domain ontology atlas supports cross-domain reasoning, a GNN-RL model predicts an attack path, protection logic is verified through double-target-range simulation, and the method is high in reliability and high in reliability. The intention-driven mechanism realizes second-level response, and a complete closed loop from threat perception to adaptive protection is formed.
Owner:GUIZHOU POWER GRID CO LTD

Airborne synthetic visual dynamic threat intelligent identification system based on multi-source fusion

The invention belongs to the technical field of avionics, and particularly discloses an airborne synthetic visual dynamic threat intelligent identification system based on multi-source fusion, which comprises a multi-source data acquisition module, an integrated GNSS unit, an IMU unit, a camera, a laser radar and a millimeter wave radar, and is used for acquiring images, point cloud and meteorological data of a flight environment through a space-time calibration mechanism; the dynamic threat analysis module is used for performing fusion processing on the multi-source data, identifying a dynamic threat target based on a target detection model and outputting a threat level; and the visual scene display module is used for dynamically adjusting the display content and the alarm mode of the synthetic visual scene according to the threat level in combination with the eye movement tracking data and the flight stage information. The problems that a traditional synthetic visual system is lagged in dynamic threat perception, insufficient in multi-source data fusion and low in man-machine interaction efficiency are solved, and the situation awareness and safety guarantee capability of an aircraft in a complex airspace environment is remarkably improved.
Owner:XIAN SOGYA AVIATION TECH CO LTD

Threat sensing system based on active domain name generation and real-time malicious domain name detection

The invention discloses a threat sensing system based on active domain name generation and real-time malicious domain name detection, and belongs to the technical field of network security detection. The system comprises a historical threat sensing module, a real-time threat sensing module and a malicious detection module. In the historical threat sensing module, a domain name generation module constructs a similar domain name generation model by using an autoregression model based on Transform and generates a similar domain name list of a target enterprise, a risk assessment module detects whether similar domain names are registered or not, and if the similar domain names are registered and can be accessed, the similar domain names are added into a to-be-detected list; the real-time threat sensing module monitors newly registered domain names in real time, and adds the newly registered domain names into a suspicious domain name list if the similarity between the newly registered domain names and the target enterprise domain names is high; and the malicious detection module detects the list to be detected and the suspicious domain name list and identifies phishing websites. The domain name generated by the system can keep high similarity with the real domain name of an enterprise visually and semantically, and the potential domain name abuse risk can be quickly identified and evaluated.
Owner:BEIJING UNIV OF POSTS & TELECOMM

Network security protection method for power monitoring system

The invention discloses a network security protection method for an electric power monitoring system, relates to the technical field of electric power network security operation and maintenance, and can more effectively identify high-concealment attacks which are dynamically renamed or permeated by using system vulnerabilities through a constructed risk instruction feature database. Then, the received network access request is subjected to multi-dimensional analysis, the defect of an existing system on multi-dimensional instruction verification is overcome, secondary biological feature authentication is introduced for high-risk operation in a benign process, a digital signature verification mechanism is started for file transmission, an endogenous safety barrier of the system is directly reinforced, and the safety of the system is improved. A machine learning algorithm is applied to analyze the compliance of an instruction sequence, and real-time risk early warning is performed on an instruction stream deviating from a normal mode, so that the problem of insufficient dynamic threat perception of an existing system is solved, and the dynamic defense capability and the full-life-cycle safety control level of the power monitoring system in a complex network environment are remarkably enhanced.
Owner:SICHUAN ENERGY INVESTMENT YIBIN XUZHOU ELECTRIC POWER CO LTD

Cloud honey point dynamic arrangement method and system based on software-defined spoofing defense

The invention provides a cloud honey point dynamic arrangement method and system based on software-defined spoofing defense, and the system comprises a base construction control layer and an execution layer based on software-defined spoofing defense, the control layer comprises a threat sensing unit, a game decision unit and an arrangement control unit, the execution layer comprises a cloud native arrangement unit and a defense resource library; the threat sensing unit collects threat intelligence and generates a structured intelligence object; the game decision-making unit is used for game solving of an optimal response strategy; the arrangement control unit reads the defense strategy state data, generates a strategy configuration instruction according to the optimal response strategy, and issues the strategy configuration instruction to the cloud native arrangement unit; the cloud native arrangement unit responds to the instruction and dispatches a defense resource library to instantiate a Pod comprising a honey point container and a distributed feedback component; the defense resource library is used for maintaining honey point configuration files for generating honey point instances. By applying the system, self-adaptive closed-loop active defense can be realized.
Owner:GUANGZHOU UNIVERSITY +1

A method for security threat perception and detection of global network devices

ActiveCN121841825BInternet trafficAttack
This invention discloses a security threat perception and detection method for global network devices. It simultaneously collects three types of data: network traffic, behavior logs, and attack characteristics, forming multi-dimensional factual evidence. The method utilizes a firework algorithm to optimize the deployment of logical monitoring points (feature nodes) in the virtual network and calculates the dynamic intensity of threat propagation at each point, thereby constructing a node-level threat field that quantifies the spatial distribution of threats. Subsequently, peak, mean, and dispersion indicators are extracted, and behavioral load, threat polarization, and cumulative threat indicators are calculated from the raw data, forming a six-dimensional vector. This vector is input into a pre-trained global threat level classification model, outputting a discrete threat level. Finally, based on this level, firewall rules, intrusion detection feature libraries, and other protection strategies are dynamically adjusted to achieve automatic matching of security configuration and threat posture.
Owner:BEIJING SHANGZHANG INFORMATION TECHNOLOGY CO LTD

Network threat perception and defense strategy optimization system and method based on machine learning

ActiveCN119996009BSecuring communicationSingle sessionEngineering
The present invention belongs to the field of network security technology, and discloses a network threat perception and defense strategy optimization system and method based on machine learning; the method comprises: obtaining traffic level data, log level data and user level data in a single session; constructing original samples based on the traffic level data, log level data and user level data, inputting the original samples into a pre-trained anomaly recognition model, and outputting corresponding network information categories; constructing adversarial samples based on the original samples; merging the adversarial samples and the original samples into an expanded training set, annotating the adversarial samples with the network information categories corresponding to the original samples, and then performing secondary training on the anomaly recognition model to obtain an adversarially optimized anomaly recognition model; the present invention effectively improves the protection capability of the network.
Owner:GANSU JIANYUE INFORMATION TECHNOLOGY CO LTD

Industrial cloud side-end collaborative security situation awareness method and device

The invention discloses an industrial cloud side-end collaborative security situation awareness method and device, and relates to the technical field of industrial internet and information security, and the method comprises the steps: obtaining a device-level security event through anomaly detection and white list verification based on original security data reported by a terminal device; carrying out aggregation analysis on the events on the edge side by utilizing a lightweight rule base, and generating an edge domain level local security situation; fusing a multi-edge domain situation at a cloud end, and performing global association reasoning by means of a knowledge graph and a graph neural network to form a system-level security situation; and finally, generating a hierarchical early warning and response strategy according to the global situation, and supporting dynamic optimization of a rule base and a knowledge graph based on feedback. Through the above mode, efficient cooperative processing and intelligent analysis of industrial security data at three levels of end, edge and cloud are realized, and the real-time performance, the accuracy and the response capability of threat perception of a large-scale industrial system are improved.
Owner:CGN INTELLECTUAL TECH SHENZHEN CO LTD

Full-flow threat sensing and tracing system oriented to cloud native environment

The invention belongs to the technical field of cloud native environments, and particularly relates to a cloud native environment-oriented full-flow threat sensing and tracing system, which comprises a data acquisition layer deployed on each computing node of a cloud native cluster and used for acquiring east-west network flow and north-south network flow; the data preprocessing and storage layer is connected with the data acquisition layer, and is used for performing analysis, specification and standardization processing on the acquired original traffic and storing the processed original traffic as a structured traffic log; the dynamic strategy engine is connected with the data preprocessing and storage layer and is used for generating and adjusting a security strategy based on a real-time flow analysis result; and carrying out visualization and traceability analysis. According to the invention, through multi-level data acquisition and fusion, all-around deep monitoring of network activities in a cloud native environment is realized, and specifically, an eBPF probe is deployed on a kernel layer of an operating system in a data acquisition layer, so that basic network connections and data packets of all Pods can be captured without invasion.
Owner:SHAOYANG JINXIN TECHNOLOGY CO LTD

A city network security multidimensional monitoring management system and method

ActiveCN120342674BSecuring communicationCentralized managementUrban network
The application discloses a kind of urban network security multidimensional monitoring management system and method, comprising: threat perception probe, deployment is in the center of the unit of the monitored city network and each node bypass, for threat detection processing;Full-flow collector, deployment is in the center of the unit of the monitored city network and each node bypass, for evidence tracing processing;Threat perception system is used to the threat perception probe and full-flow collector of each node are centrally managed;The centralized management includes unified monitoring, unified management, unified upgrade, centralized strategy issue, threat analysis and threat hunting. Avoid each security product fight each other, and then centralized management, improve threat detection capability, trace source, realize the efficient management of multiple kinds of security products, and multidimensional monitoring management is carried out to city network security.
Owner:盐城市大数据集团有限公司

An industrial control system intrusion detection method based on personalized federated learning

The application belongs to the technical field of personalized federated learning, and discloses an industrial control system intrusion detection method based on personalized federated learning. The method solves the problem of insufficient model generalization ability under Non-IID data, realizes the balance between local adaptability and global threat perception through similar client cooperative learning, and proposes a similarity calculation mechanism based on JS divergence to realize collaborative modeling between similar clients, thereby ensuring personalization and enhancing global knowledge sharing ability. An industrial network feature extraction tool is designed to support Session, Flow and Stream three-layer modeling, extract high semantic features of industrial protocols, and improve the quality of model training data. The tool has industrial protocol perception ability, can extract various high semantic features from various key industrial control protocols, effectively support the standardized conversion of multi-entity data sources, and enhance the representativeness and difference of model training data.
Owner:NORTHEASTERN UNIV CHINA

A threat perception system based on active domain name generation and real-time detection of malicious domain names

The application discloses a threat perception system based on active domain name generation and real-time detection of malicious domain names, and belongs to the technical field of network security detection. The system comprises a historical threat perception module, a real-time threat perception module and a malicious detection module. In the historical threat perception module, a domain name generation module uses a self-recurrence model based on a Transformer to construct a similar domain name generation model, generates a similar domain name list of a target enterprise, and a risk assessment module detects whether the similar domain names have been registered; if yes, the similar domain names can be accessed and added to a detection list. The real-time threat perception module monitors newly registered domain names in real time, and adds domain names with high similarity to the target enterprise domain names to a suspicious domain name list. The malicious detection module detects the detection list and the suspicious domain name list, and identifies phishing websites. The domain names generated by the system can be highly similar to the real domain names of an enterprise in terms of vision and semantics, and can rapidly identify and evaluate potential domain name abuse risks.
Owner:BEIJING UNIV OF POSTS & TELECOMM

Deep threat perception system based on network security

PendingCN122027329ASecuring communicationComplex event processingBusiness enterprise
The invention discloses a deep threat sensing system based on network security, which is applied to a security operation platform system and is characterized by comprising a threat sensing module for performing threat detection on capabilities of a terminal side, a network side and a platform side respectively; the association analysis module is used for realizing complex CEP semantics based on a CEP complex event processing engine in combination with various association rule templates, performing timeline association and causal inference on data collected by a terminal side and a network side and cloud factors, and generating an association event of a platform side; and the emergency disposal module configures response atomic operation and response object intelligent recommendation, performs role division on response objects, and intelligently recommends different disposal modes for different roles. According to the scheme, the value of a complete security closed loop in various security scenes is brought, the security operation efficiency is improved, the threshold of operators is reduced, and all-around network security protection is provided for enterprises and individuals in a security operation system.
Owner:TANGSHAN DUNSHI INFORMATION TECH CO LTD

Multi-source threat strategy generation method and system of unmanned aerial vehicle navigation decoy data integrated computing system

The invention provides a multi-source threat strategy generation method and system of an unmanned aerial vehicle navigation decoy data integrated computing system. According to the method, navigation signal data and multi-source threat perception data of an unmanned aerial vehicle are acquired, the multi-source threat perception data comprises geographic space radio frequency fingerprints and visual trajectory features, the geographic space radio frequency fingerprints and the visual trajectory features are fused to generate a dynamic threat situation map, and the dynamic threat situation map is generated based on an antigen-antibody reaction mechanism. Constructing a matching relationship between the dynamic threat situation map and an unmanned aerial vehicle navigation protocol vulnerability library, identifying semantic ambiguity points which can be utilized, and finally generating a navigation decoy strategy under the constraint of navigation signal space time; according to the technical scheme provided by the invention, accurate identification and adaptive response to the abnormal behavior of the unmanned aerial vehicle and the navigation protocol vulnerability are realized; and the naturalness and the concealment of the decoy process are ensured, and the reliability and the environmental adaptability of unmanned aerial vehicle guidance are improved.
Owner:ZHONGLIAN GOLDEN CROWN INFORMATION TECH (BEIJING) CO LTD

Email threat perception system

PendingCN122179195ASecuring communicationSpammingPerception system
The application provides an email threat perception system, belonging to the field of network security and email protection, and researches and practices email security threat perception technology, utilizes an email behavior detection model and a machine learning model to perform multi-dimensional and multi-level deep analysis on emails, so as to identify abnormal email behaviors, discover phishing links and sensitive contents, etc. On this basis, an active and low false alarm rate email security threat perception system is realized, which detects and filters spam emails, phishing emails and emails containing sensitive contents, and improves the security of email applications.
Owner:GUILIN UNIV OF ELECTRONIC TECH

Threat perception method and device of information system based on human body internal perception mechanism, electronic equipment and storage medium

The invention discloses a threat perception method and device of an information system based on a human body internal perception mechanism, electronic equipment and a storage medium. The method comprises the steps that under the condition that an information system is started, n micro-sensing features and target operation in a micro-sensing feature library are monitored through a micro-sensing probe, a monitoring result is obtained, a micro-sensing center is arranged in the information system, and the micro-sensing center at least comprises the micro-sensing feature library, the target operation and the target operation, the target operation is an unauthorized operation oriented to the micro-sensing center; when the monitoring result indicates that no abnormal micro-sensing feature exists in the information system and the target operation is not monitored, determining that the information system is in a safe state; and under the condition that the monitoring result indicates that the abnormal micro-sensing feature exists in the information system and / or the target operation is monitored, sensing a threat category existing in the information system and a system state of the information system.
Owner:ZHENGZHOU UNIV +1

Pilot dynamic assessment method, system, device and storage medium based on TEM model

The application relates to the technical field of TEM model, and provides a pilot dynamic evaluation method, system and device based on a TEM model and a storage medium, which solves the problems of low precision of flight training evaluation and poor adaptability of training schemes. The method comprises the following steps: obtaining flight control, physiological monitoring and cockpit voice data, forming a multi-modal data stream through time synchronization; using a TEM model to perform threat perception, error management and non-technical skill three-level evaluation, generate corresponding indexes and fuse them into a comprehensive feature vector; using a double-channel long short-term memory network to process time sequence and cognitive features respectively, and extracting deep features; using SHAP values for decision tracing to locate the ability defect nodes; and finally matching the defect types through a personalized improvement scheme recommendation mechanism, and generating adaptive training content. The application improves the precision of flight training evaluation and the adaptability of training schemes.
Owner:CHINA SOUTHERN TECHNOLOGY (GUANGDONG HENGQIN) CO LTD +2

Industry security joint defense method based on federal game

PendingCN122293431AMulti source dataInter organizational
This application relates to the field of industry security joint defense technology and discloses an industry security joint defense method based on federated game theory. This method collects multi-source data reported by each joint defense member, performs cross-organizational correlation analysis on threat perception data to identify early threat signals spreading across multiple organizations, thereby quantifying the threat pressure experienced by each member. It then assesses the cooperation risk by combining the resource status and behavioral characteristics of each member, and further infers the diffusion process of risk from individual members to the overall joint defense network based on cooperation risk and trust assessment data. Finally, it generates collaborative tasks and incentive constraint schemes for each member based on the risk evolution prediction results. This application achieves early identification of cross-organizational threats and quantitative assessment of cooperation risks, and can generate differentiated collaborative defense schemes in the early stages of threat diffusion, improving the overall defense effectiveness of the industry joint defense system.
Owner:NANJING SWIFT SAFETY TECH CO LTD

Concealed threat sensing method and system based on side channel signal

The invention relates to the technical field of communication, and discloses a hidden threat sensing method and system based on a side channel signal, and the system comprises an acquisition processing module which determines a signal fluctuation amplitude based on a network prediction signal model and a first side channel signal, the communication environment is judged according to the relation between the signal fluctuation amplitude and the second side channel signal, the time delay analysis module determines the data transmission time delay of the second side channel signal based on the communication time sequence information, and determines a time delay index value according to the standard data transmission time delay and the data transmission time delay; the time domain analysis module determines a frequency domain parameter of the second side channel signal based on the frequency domain amplitude spectrum and carries out fusion processing on the time domain parameter and the frequency domain parameter, and the threat sensing module compares the multi-dimensional feature vector with a historical time frequency library and judges whether to send out a threat early warning alarm based on a threat index value and a time delay index value. According to the method, the data transmission time delay and the time frequency characteristics are determined, so that the hidden threat sensing reliability of the communication system is ensured.
Owner:CHENGDU CHUANGXIN HUATONG INFORMATION TECH CO LTD