Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

39 results about "Threat perception" patented technology

Threat perception is defined as a deep sense of vulnerability that is assumed to be negative, likely to result in loss, and largely out of one's control (Dutton & Jackson, 1987; Jackson & Dutton, 1988) -- Glibert, 2005, 742. Threat perception is commonly viewed as a requirement to change organizational inertia.

Big data risk early warning and evaluation method based on artificial intelligence

The invention relates to the field of internet security, and discloses a big data risk early warning and evaluation method based on artificial intelligence, comprising the following steps: step S1, collecting original security data from a heterogeneous data source; s2, constructing a global causal model; s3, constructing and evolving an event causal evolution diagram so as to establish directed edges with weights among the nodes; s4, dynamically evaluating the ability level of the attacker; s5, performing adversarial intention projection; s6, calculating a dynamic risk score; and generating an early warning when the score exceeds an early warning threshold. According to the method, asymmetric information flows among event types are quantified through transfer entropy, and a context evidence fusion mechanism is combined, so that a real causal relationship and a simple statistical correlation can be distinguished; the defect that a high false alarm rate is easily generated based on rule or simple threshold matching is overcome, so that the event causal evolution diagram can accurately reflect the internal logic and time sequence characteristics of an attack behavior, and the accuracy of complex threat perception is improved.
Owner:ZHEJIANG UNIV OF SCI & TECH

Airborne synthetic visual dynamic threat intelligent identification system based on multi-source fusion

The invention belongs to the technical field of avionics, and particularly discloses an airborne synthetic visual dynamic threat intelligent identification system based on multi-source fusion, which comprises a multi-source data acquisition module, an integrated GNSS unit, an IMU unit, a camera, a laser radar and a millimeter wave radar, and is used for acquiring images, point cloud and meteorological data of a flight environment through a space-time calibration mechanism; the dynamic threat analysis module is used for performing fusion processing on the multi-source data, identifying a dynamic threat target based on a target detection model and outputting a threat level; and the visual scene display module is used for dynamically adjusting the display content and the alarm mode of the synthetic visual scene according to the threat level in combination with the eye movement tracking data and the flight stage information. The problems that a traditional synthetic visual system is lagged in dynamic threat perception, insufficient in multi-source data fusion and low in man-machine interaction efficiency are solved, and the situation awareness and safety guarantee capability of an aircraft in a complex airspace environment is remarkably improved.
Owner:XIAN SOGYA AVIATION TECH CO LTD

Cloud honey point dynamic arrangement method and system based on software-defined spoofing defense

The invention provides a cloud honey point dynamic arrangement method and system based on software-defined spoofing defense, and the system comprises a base construction control layer and an execution layer based on software-defined spoofing defense, the control layer comprises a threat sensing unit, a game decision unit and an arrangement control unit, the execution layer comprises a cloud native arrangement unit and a defense resource library; the threat sensing unit collects threat intelligence and generates a structured intelligence object; the game decision-making unit is used for game solving of an optimal response strategy; the arrangement control unit reads the defense strategy state data, generates a strategy configuration instruction according to the optimal response strategy, and issues the strategy configuration instruction to the cloud native arrangement unit; the cloud native arrangement unit responds to the instruction and dispatches a defense resource library to instantiate a Pod comprising a honey point container and a distributed feedback component; the defense resource library is used for maintaining honey point configuration files for generating honey point instances. By applying the system, self-adaptive closed-loop active defense can be realized.
Owner:GUANGZHOU UNIVERSITY +1

A method for security threat perception and detection of global network devices

ActiveCN121841825BInternet trafficAttack
This invention discloses a security threat perception and detection method for global network devices. It simultaneously collects three types of data: network traffic, behavior logs, and attack characteristics, forming multi-dimensional factual evidence. The method utilizes a firework algorithm to optimize the deployment of logical monitoring points (feature nodes) in the virtual network and calculates the dynamic intensity of threat propagation at each point, thereby constructing a node-level threat field that quantifies the spatial distribution of threats. Subsequently, peak, mean, and dispersion indicators are extracted, and behavioral load, threat polarization, and cumulative threat indicators are calculated from the raw data, forming a six-dimensional vector. This vector is input into a pre-trained global threat level classification model, outputting a discrete threat level. Finally, based on this level, firewall rules, intrusion detection feature libraries, and other protection strategies are dynamically adjusted to achieve automatic matching of security configuration and threat posture.
Owner:BEIJING SHANGZHANG INFORMATION TECHNOLOGY CO LTD

Industrial cloud side-end collaborative security situation awareness method and device

The invention discloses an industrial cloud side-end collaborative security situation awareness method and device, and relates to the technical field of industrial internet and information security, and the method comprises the steps: obtaining a device-level security event through anomaly detection and white list verification based on original security data reported by a terminal device; carrying out aggregation analysis on the events on the edge side by utilizing a lightweight rule base, and generating an edge domain level local security situation; fusing a multi-edge domain situation at a cloud end, and performing global association reasoning by means of a knowledge graph and a graph neural network to form a system-level security situation; and finally, generating a hierarchical early warning and response strategy according to the global situation, and supporting dynamic optimization of a rule base and a knowledge graph based on feedback. Through the above mode, efficient cooperative processing and intelligent analysis of industrial security data at three levels of end, edge and cloud are realized, and the real-time performance, the accuracy and the response capability of threat perception of a large-scale industrial system are improved.
Owner:CGN INTELLECTUAL TECH SHENZHEN CO LTD

Full-flow threat sensing and tracing system oriented to cloud native environment

The invention belongs to the technical field of cloud native environments, and particularly relates to a cloud native environment-oriented full-flow threat sensing and tracing system, which comprises a data acquisition layer deployed on each computing node of a cloud native cluster and used for acquiring east-west network flow and north-south network flow; the data preprocessing and storage layer is connected with the data acquisition layer, and is used for performing analysis, specification and standardization processing on the acquired original traffic and storing the processed original traffic as a structured traffic log; the dynamic strategy engine is connected with the data preprocessing and storage layer and is used for generating and adjusting a security strategy based on a real-time flow analysis result; and carrying out visualization and traceability analysis. According to the invention, through multi-level data acquisition and fusion, all-around deep monitoring of network activities in a cloud native environment is realized, and specifically, an eBPF probe is deployed on a kernel layer of an operating system in a data acquisition layer, so that basic network connections and data packets of all Pods can be captured without invasion.
Owner:SHAOYANG JINXIN TECHNOLOGY CO LTD

A city network security multidimensional monitoring management system and method

ActiveCN120342674BSecuring communicationCentralized managementUrban network
The application discloses a kind of urban network security multidimensional monitoring management system and method, comprising: threat perception probe, deployment is in the center of the unit of the monitored city network and each node bypass, for threat detection processing;Full-flow collector, deployment is in the center of the unit of the monitored city network and each node bypass, for evidence tracing processing;Threat perception system is used to the threat perception probe and full-flow collector of each node are centrally managed;The centralized management includes unified monitoring, unified management, unified upgrade, centralized strategy issue, threat analysis and threat hunting. Avoid each security product fight each other, and then centralized management, improve threat detection capability, trace source, realize the efficient management of multiple kinds of security products, and multidimensional monitoring management is carried out to city network security.
Owner:盐城市大数据集团有限公司

An industrial control system intrusion detection method based on personalized federated learning

The application belongs to the technical field of personalized federated learning, and discloses an industrial control system intrusion detection method based on personalized federated learning. The method solves the problem of insufficient model generalization ability under Non-IID data, realizes the balance between local adaptability and global threat perception through similar client cooperative learning, and proposes a similarity calculation mechanism based on JS divergence to realize collaborative modeling between similar clients, thereby ensuring personalization and enhancing global knowledge sharing ability. An industrial network feature extraction tool is designed to support Session, Flow and Stream three-layer modeling, extract high semantic features of industrial protocols, and improve the quality of model training data. The tool has industrial protocol perception ability, can extract various high semantic features from various key industrial control protocols, effectively support the standardized conversion of multi-entity data sources, and enhance the representativeness and difference of model training data.
Owner:NORTHEASTERN UNIV CHINA

Deep threat perception system based on network security

PendingCN122027329ASecuring communicationComplex event processingBusiness enterprise
The invention discloses a deep threat sensing system based on network security, which is applied to a security operation platform system and is characterized by comprising a threat sensing module for performing threat detection on capabilities of a terminal side, a network side and a platform side respectively; the association analysis module is used for realizing complex CEP semantics based on a CEP complex event processing engine in combination with various association rule templates, performing timeline association and causal inference on data collected by a terminal side and a network side and cloud factors, and generating an association event of a platform side; and the emergency disposal module configures response atomic operation and response object intelligent recommendation, performs role division on response objects, and intelligently recommends different disposal modes for different roles. According to the scheme, the value of a complete security closed loop in various security scenes is brought, the security operation efficiency is improved, the threshold of operators is reduced, and all-around network security protection is provided for enterprises and individuals in a security operation system.
Owner:TANGSHAN DUNSHI INFORMATION TECH CO LTD

Multi-source threat strategy generation method and system of unmanned aerial vehicle navigation decoy data integrated computing system

ActiveCN121721664ASatellite radio beaconingUncrewed vehicleAntigen-antibody reactions
The invention provides a multi-source threat strategy generation method and system of an unmanned aerial vehicle navigation decoy data integrated computing system. According to the method, navigation signal data and multi-source threat perception data of an unmanned aerial vehicle are acquired, the multi-source threat perception data comprises geographic space radio frequency fingerprints and visual trajectory features, the geographic space radio frequency fingerprints and the visual trajectory features are fused to generate a dynamic threat situation map, and the dynamic threat situation map is generated based on an antigen-antibody reaction mechanism. Constructing a matching relationship between the dynamic threat situation map and an unmanned aerial vehicle navigation protocol vulnerability library, identifying semantic ambiguity points which can be utilized, and finally generating a navigation decoy strategy under the constraint of navigation signal space time; according to the technical scheme provided by the invention, accurate identification and adaptive response to the abnormal behavior of the unmanned aerial vehicle and the navigation protocol vulnerability are realized; and the naturalness and the concealment of the decoy process are ensured, and the reliability and the environmental adaptability of unmanned aerial vehicle guidance are improved.
Owner:ZHONGLIAN GOLDEN CROWN INFORMATION TECH (BEIJING) CO LTD

Email threat perception system

PendingCN122179195ASecuring communicationSpammingPerception system
The application provides an email threat perception system, belonging to the field of network security and email protection, and researches and practices email security threat perception technology, utilizes an email behavior detection model and a machine learning model to perform multi-dimensional and multi-level deep analysis on emails, so as to identify abnormal email behaviors, discover phishing links and sensitive contents, etc. On this basis, an active and low false alarm rate email security threat perception system is realized, which detects and filters spam emails, phishing emails and emails containing sensitive contents, and improves the security of email applications.
Owner:GUILIN UNIV OF ELECTRONIC TECH

Pilot dynamic assessment method, system, device and storage medium based on TEM model

The application relates to the technical field of TEM model, and provides a pilot dynamic evaluation method, system and device based on a TEM model and a storage medium, which solves the problems of low precision of flight training evaluation and poor adaptability of training schemes. The method comprises the following steps: obtaining flight control, physiological monitoring and cockpit voice data, forming a multi-modal data stream through time synchronization; using a TEM model to perform threat perception, error management and non-technical skill three-level evaluation, generate corresponding indexes and fuse them into a comprehensive feature vector; using a double-channel long short-term memory network to process time sequence and cognitive features respectively, and extracting deep features; using SHAP values for decision tracing to locate the ability defect nodes; and finally matching the defect types through a personalized improvement scheme recommendation mechanism, and generating adaptive training content. The application improves the precision of flight training evaluation and the adaptability of training schemes.
Owner:CHINA SOUTHERN TECHNOLOGY (GUANGDONG HENGQIN) CO LTD +2

Industry security joint defense method based on federal game

PendingCN122293431AMulti source dataInter organizational
This application relates to the field of industry security joint defense technology and discloses an industry security joint defense method based on federated game theory. This method collects multi-source data reported by each joint defense member, performs cross-organizational correlation analysis on threat perception data to identify early threat signals spreading across multiple organizations, thereby quantifying the threat pressure experienced by each member. It then assesses the cooperation risk by combining the resource status and behavioral characteristics of each member, and further infers the diffusion process of risk from individual members to the overall joint defense network based on cooperation risk and trust assessment data. Finally, it generates collaborative tasks and incentive constraint schemes for each member based on the risk evolution prediction results. This application achieves early identification of cross-organizational threats and quantitative assessment of cooperation risks, and can generate differentiated collaborative defense schemes in the early stages of threat diffusion, improving the overall defense effectiveness of the industry joint defense system.
Owner:NANJING SWIFT SAFETY TECH CO LTD

Concealed threat sensing method and system based on side channel signal

The invention relates to the technical field of communication, and discloses a hidden threat sensing method and system based on a side channel signal, and the system comprises an acquisition processing module which determines a signal fluctuation amplitude based on a network prediction signal model and a first side channel signal, the communication environment is judged according to the relation between the signal fluctuation amplitude and the second side channel signal, the time delay analysis module determines the data transmission time delay of the second side channel signal based on the communication time sequence information, and determines a time delay index value according to the standard data transmission time delay and the data transmission time delay; the time domain analysis module determines a frequency domain parameter of the second side channel signal based on the frequency domain amplitude spectrum and carries out fusion processing on the time domain parameter and the frequency domain parameter, and the threat sensing module compares the multi-dimensional feature vector with a historical time frequency library and judges whether to send out a threat early warning alarm based on a threat index value and a time delay index value. According to the method, the data transmission time delay and the time frequency characteristics are determined, so that the hidden threat sensing reliability of the communication system is ensured.
Owner:CHENGDU CHUANGXIN HUATONG INFORMATION TECH CO LTD

Asset simulation system for threat perception

The invention provides an asset simulation system for threat awareness, which comprises a simulation module, a decision module, a semantic mapping library, a response agent, a resource storage module and a session library, and is characterized in that when an access request of an attacker is received, the decision module firstly matches a resource type corresponding to the request through the semantic mapping library, and if the request is static resource access, the response agent is started; the decision-making module directly calls the static simulation resources in the resource storage module and returns a response, and if the access is dynamic resource access, the decision-making module triggers a response agent, so that the response agent is started and dynamically interacts with an attacker, an interaction log is recorded, and a session context is synchronously updated to a session library. According to the method, high-fidelity replication of static and dynamic resources of protected assets is realized based on a large vertical model, and through hierarchical design, quick response can be performed on static resource access, and deep interaction can be performed on dynamic resource access.
Owner:GUANGZHOU UNIVERSITY

Network DOS attack defense method and equipment based on dynamic resource isolation and data protection

The invention discloses a network DOS attack defense method and device based on dynamic resource isolation and data protection and a storage medium, and belongs to the technical field of network security. The method comprises the following core steps: collecting network flow data and system resource data of network equipment in real time; a behavior entropy is calculated based on the flow data, a resource pressure index is calculated based on the system resource data, and the behavior entropy and the resource pressure index are weighted and fused to generate a dynamic threat score; and determining a defense level from the multi-level defense strategy according to the score. According to the method, through dynamic threat perception, process-level deep dormancy and hardware isolation, the attack pre-judgment capability, the service continuity and the system toughness are remarkably improved, and the core data security under extreme conditions is effectively guaranteed.
Owner:TECHNICOLOR (CHINA) TECH CO LTD

Intelligent dynamic threat perception-based credential security enhancement method and system

The invention provides a credential security enhancement method and system for intelligent dynamic threat perception. According to the method, four-dimensional original monitoring data covering a physical layer, a system layer, a data layer and an application layer is collected through a probe deployed at a core node of the credential environment, and a standardized time sequence matrix is formed after unified processing. A space-time diagram neural network is used for identifying known threats, sandbox simulation is carried out on unknown threats through a reinforcement learning driven confrontation deduction engine, and an extended threat portrait is generated. Based on this, a defense strategy is dynamically generated through multi-objective optimization in combination with a system resource state and a service priority, and the defense strategy is cooperatively executed by a multi-agent module. In the whole process, credible evidence storage is carried out through the block chain, a self-calibration closed loop based on efficiency evaluation is established, and continuous evolution of the protection capability is realized. The system effectively improves the real-time perception, intelligent response and credible traceability of the credential environment to known and unknown threats.
Owner:STATE GRID QINGHAI ELECTRIC POWER COMPANY +1

A cloud honey point dynamic arrangement method and system based on software-defined deception defense

The application provides a cloud honeypot dynamic arrangement method and system based on software-defined deception defense, the system comprises a base construction control layer and an execution layer based on software-defined deception defense, the control layer comprises a threat perception unit, a game decision unit and an arrangement control unit, and the execution layer comprises a cloud native arrangement unit and a defense resource library; the threat perception unit collects threat intelligence and generates a structured intelligence object; the game decision unit is used for game solving of an optimal response strategy; the arrangement control unit reads defense strategy state data and generates a strategy configuration instruction according to the optimal response strategy, and the strategy configuration instruction is issued to the cloud native arrangement unit; the cloud native arrangement unit responds to the instruction, schedules the defense resource library to instantiate a Pod containing a honeypot container and a distributed feedback component; and the defense resource library maintains a honeypot configuration file used for generating a honeypot instance. Application of the system can realize adaptive closed-loop active defense.
Owner:GUANGZHOU UNIVERSITY +1

A mobile terminal intelligent security threat perception method based on user behavior modeling

The application discloses a kind of mobile terminal intelligent security threat perception methods based on user behavior modeling, it is related to mobile terminal intelligent security threat perception field, including: through mobile terminal acquisition low privacy risk metadata, establish local metadata database;Based on historical security threat case and simulation attack experiment, construct user behavior graph and train graph neural network teacher model;Based on the knowledge output of graph neural network teacher model, construct lightweight child model, and deploy to mobile terminal;Terminal output local threat prediction result sequence, while calculating the distribution entropy value of total time length and personal historical baseline deviation score;Terminal data is uploaded to cloud, based on graph neural network teacher model, generates response instruction and carries out regulation and control to mobile terminal detection.The application has the advantages that: under the premise of guaranteeing user privacy security throughout, adapting to mobile terminal resource constraint, realize the individualization, high accuracy, dynamic perception and accurate regulation and control to security threat.
Owner:GUANGDONG POWER GRID CO LTD INFORMATION CENT

Network attack hierarchical detection model training method, detection method and device

The application provides a network attack hierarchical detection model training method, a detection method and equipment. The training method comprises: based on a hierarchical label system containing attack scene labels and attack type labels, using a graph attention network to encode the hierarchical relationship; using the encoding result and network traffic data to train a classification model based on prompt learning, outputting a collaborative prediction result of attack scenes and types by calculating the similarity between traffic prompt representation and global label embedding; determining a supervision signal according to real labels, optimizing the classification model through adversarial training, and obtaining a final detection model. The application can realize collaborative identification and hierarchical tracing of attack scenes and types, provide more fine-grained threat perception, significantly improve the robustness, generalization ability and detection stability of the model in a dynamic adversarial environment, thereby improving the network attack identification accuracy, and improving the accuracy and efficiency of network security operation and maintenance.
Owner:BEIJING UNIV OF POSTS & TELECOMM

Power plant intelligent safety perception and automatic response system and method based on MCP

The invention provides an MCP-based power plant intelligent safety perception and automatic response system and method, and the system comprises a data access module which is used for achieving the standardized collection and processing of multi-source heterogeneous data of a power plant through a multi-class MCP server; the multi-stage detection module is used for realizing comprehensive threat perception by adopting a three-stage mechanism of grammar detection, behavior analysis and correlation analysis; the intelligent analysis module is used for performing deep threat research and judgment and influence evaluation based on a large language model; the decision execution module is used for starting a differentiated man-machine collaborative response process according to the threat level; and the knowledge management module is used for realizing continuous evolution of the system capability through case library learning and a feedback mechanism. According to the invention, intelligent perception, accurate research and judgment and cooperative response of power plant industrial control network security threats are realized, and the automation level and the operation and maintenance efficiency of power plant network security protection are effectively improved.
Owner:HUANENG POWER INT INC +1

A multi-source threat strategy generation method and system of a drone navigation deception data set integration computing system

The application provides a multi-source threat strategy generation method and system of a UAV navigation deception data integrated computing system. First, the navigation signal data of the UAV and multi-source threat perception data are obtained, wherein the multi-source threat perception data includes geographic space radio frequency fingerprints and visual trajectory features. Second, the geographic space radio frequency fingerprints and visual trajectory features are fused to generate a dynamic threat situation map. Third, based on the antigen-antibody reaction mechanism, a matching relationship between the dynamic threat situation map and the UAV navigation protocol vulnerability library is constructed, and semantic ambiguity points that can be exploited are identified. Finally, navigation deception strategies are generated under the constraints of the navigation signal space-time. The technical solution provided by the application not only realizes accurate identification and adaptive response of abnormal behaviors of the UAV and navigation protocol vulnerabilities, but also ensures the naturalness and concealment of the deception process, and improves the reliability and environmental adaptability of the UAV guidance.
Owner:ZHONGLIAN GOLDEN CROWN INFORMATION TECH (BEIJING) CO LTD

An intelligent threat perception method and system fusing honeynet and honeypot

The application provides a kind of intelligent threat perception method and system of fusing honeycomb and honeypot, it is related to threat perception technical field.The method provided by the application comprises: effective threat perception request set is returned to corresponding terminal equipment, at least one is selected from the returned set as a threat perception request to be executed and is re-submitted to server, the first time information and the second time information are calculated for each threat perception request to be executed, the window adaptability is verified according to the comparison result of the first time information and the second time information, according to the first time information and the second time information verification result, the deception capture task corresponding to target network domain coordinates is arranged to the task list selected position of selected honeypot / honeycomb node, and is issued to execute.The application calculates the link ready time and the node exposure time, effectively avoids the data loss problem caused by the delay of acquisition link, and supports automatic rearrangement and fallback strategy, improves the reliability and data integrity of deployment.
Owner:INFORMATION & COMMNUNICATION BRANCH STATE GRID JIANGXI ELECTRIC POWER CO

Self-adaptive defense method and system, computer equipment and storage medium

The invention provides a self-adaptive defense method and system, computer equipment and a storage medium, and belongs to the technical field of network and information security, and the method comprises the steps: collecting abnormal network state data when a target network is attacked, and automatically extracting attack feature elements from the abnormal network state data; and generating an accurate network detection rule in real time according to the elements, and dynamically loading the network detection rule to a flow detection engine through a hot update technology, thereby realizing rapid perception and alarm of unknown threats. Suspicious processes are positioned through port-process mapping, and remote blocking, termination or isolation and other treatment actions are automatically executed; and integrating a disposal record and a system log to construct an attack causal graph, forming a complete and visual attack evidence chain, and supporting influence range evaluation and defense strategy iterative optimization. According to the method, thorough defense from threat perception, rule generation, real-time blocking to traceability analysis is realized, and the autonomous response and dynamic adaptive capacity of the network in facing novel and complex attacks are effectively improved.
Owner:SHANDONG UNIV OF TECH

Threat perception method and device for intrusion detection model

The application provides a threat perception method and device for an intrusion detection model, wherein the threat perception method for the intrusion detection model comprises: obtaining vehicle detection data; inputting the vehicle detection data into a heterogeneous intrusion detection model pool to obtain detection results output by each heterogeneous intrusion detection model; perceiving an abnormal intrusion detection model in the heterogeneous intrusion detection model pool based on the detection results; determining a threat perception result of the heterogeneous intrusion detection model pool based on the detection results; and performing cleaning processing on the abnormal intrusion detection model in the case that the abnormal intrusion detection model is perceived in the heterogeneous intrusion detection model pool. Through the above method, the abnormal state of the heterogeneous intrusion detection model pool being disturbed or attacked by a network can be actively perceived, the endogenous safety of vehicle networking anomaly detection is enhanced, and the ability of actively perceiving network threats and defense is improved.
Owner:PURPLE MOUNTAIN LAB +2

An active network intrusion detection and defense system based on artificial intelligence

This invention belongs to the field of network security technology and discloses an artificial intelligence-based proactive network intrusion detection and prevention system, including a threat perception unit, an intelligent decision-making unit, a protocol execution unit, an intrinsic security protection unit, a security baseline policy unit, and an audit storage unit. The threat perception unit generates threat vectors based on a dual-channel neural network; the intelligent decision-making unit outputs dynamic protocol parameter combinations based on a hierarchical reinforcement learning algorithm; the protocol execution unit utilizes a resilience extension layer within the standard protocol stack to achieve seamless switching of parameters and keys without interruption through protocol resilience extension frames. The intrinsic security protection unit provides the AI ​​model with digital watermarking and integrity verification based on device identification, and in case of anomalies, it links with the security baseline policy unit to activate a fixed high-security configuration for fallback protection. This invention achieves a closed loop from intelligent perception to millisecond-level proactive defense at the protocol layer, improving the dynamic resilience of network protocols and the intrinsic security of AI.
Owner:长沙市规划信息服务中心

A covert threat perception method and system based on side channel signals

This invention relates to the field of communication technology and discloses a method and system for detecting covert threats based on side-channel signals. The system includes: an acquisition and processing module that determines signal fluctuation amplitude based on a network prediction signal model and a first side-channel signal, and determines the communication environment based on the relationship between the signal fluctuation amplitude and the second side-channel signal; a delay analysis module that determines the data transmission delay of the second side-channel signal based on communication timing information, and determines a delay index value based on a standard data transmission delay and the data transmission delay; a time-domain analysis module that determines the frequency domain parameters of the second side-channel signal based on the frequency domain amplitude spectrum, and fuses the time-domain and frequency-domain parameters; and a threat detection module that compares a multi-dimensional feature vector with a historical time-frequency database, and determines whether to issue a threat warning based on the threat index value and the delay index value. This invention ensures the reliability of the communication system's detection of covert threats by determining the data transmission delay and time-frequency characteristics.
Owner:CHENGDU CHUANGXIN HUATONG INFORMATION TECH CO LTD

Multi-source threat intelligence fusion and AI decision-making network attack adaptive response system

The invention discloses a network attack adaptive response system and method based on multi-source threat intelligence fusion and AI decision, and belongs to the technical field of network security. The method comprises the following steps: collecting heterogeneous data through a multi-source sensing layer and constructing a network space digital twinborn body updated in real time; the threat cognitive layer is based on ATTamp; the CK framework performs deep threat association analysis to generate an attacker tactical intention map; constructing a multi-agent confrontation simulation environment in a dynamic game decision engine, performing attack and defense game deduction by adopting a Monte Carlo tree search algorithm, and solving a dynamic optimal defense strategy; converting the strategy into an executable defense action plan through a strategy execution layer, and automatically issuing and executing the executable defense action plan; and finally, effect evaluation and feedback learning are carried out in an evolution verification layer to drive the system to evolve continuously. According to the method, a complete closed loop from threat perception, intelligent decision-making to autonomous evolution is realized, and the real-time performance, the self-adaptability and the confrontation intelligence level of network defense are remarkably improved.
Owner:GUANGDONG DAZHONG INFORMATION TECHNOLOGY CO LTD

Target identification-based self-adaptive hidden control method and system for ocean monitoring platform

The invention discloses a self-adaptive concealment control method and system for a marine monitoring platform based on target recognition, and belongs to the technical field of marine monitoring. The method comprises the steps that sea surface images are collected in real time through a wide-angle camera; operating the lightweight target detection model to perform threat target identification, and outputting a target bounding box coordinate, a target type label and a threat confidence coefficient; in response to the threat triggering condition being satisfied, calculating a threat level according to the threat confidence and the estimated target distance, and determining a buoyancy adjustment amount, a target depth and a silence duration based on the threat level; the gear transmission mechanism is driven to drive the parallel injector group to suck seawater to realize rapid diving; according to the marine monitoring platform, the problem that an existing marine monitoring platform lacks autonomous threat perception and active hiding and avoiding capabilities is solved, the detection accuracy is not lower than 90%, the peak power consumption is not higher than 10 W, and the silent state is maintained for 72 hours or longer.
Owner:NORTHWESTERN POLYTECHNICAL UNIV

Security threat perception detection method for global network equipment

The invention discloses a security threat perception detection method for global network equipment, which comprises the following steps of: forming a multi-dimensional fact basis by synchronously acquiring three types of data, namely network flow, behavior logs and attack characteristics, optimizing the layout of logic monitoring points (characteristic nodes) in a virtual network by using a fireworks algorithm, and calculating the threat propagation dynamic intensity of each point on the basis of the layout. Therefore, a node-level threat field for quantifying threat space distribution is constructed; then, peak value, mean value and dispersion indexes are extracted, behavior load, threat polarization and accumulated threat indexes are calculated from the original data, and a six-dimensional vector is jointly formed; inputting the vector into a pre-trained global threat level classification model, and outputting discrete threat levels; and finally, according to the level, dynamically adjusting protection strategies such as firewall rules and intrusion detection feature libraries, and realizing automatic matching of security configuration and threat situations.
Owner:BEIJING SHANGZHANG INFORMATION TECHNOLOGY CO LTD