Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

17 results about "Threatening behaviour" patented technology

Threatening behavior is intentional behavior which would cause a person of ordinary sensibilities fear of injury or harm. It can include acts of aggression such as yelling at a colleague, pounding on desks, slamming doors,blocking or cornering, and sending threatening voice-mails, e-mails, or other written threats.

Systems and methods for privacy-aware weapon anomaly detection via integrated object recognition and skeletal motion analysis

Systems, methods, and frameworks are provided for privacy-aware weapon anomaly detection via integrated object recognition and skeletal motion analysis. This framework integrates real-time object detection and motion analysis to identify weapon anomalies in video surveillance while preserving privacy. The framework combines a fine-tuned object detection model, a head-segmentation module for anonymizing unarmed individuals, and a skeleton-based motion analysis module to detect threatening behaviors. By refining and fusing detection and motion analysis outputs, the framework enhances detection accuracy and reduces false positives, thereby providing a reliable solution for intelligent, privacy-preserving surveillance applications.
Owner:FLORIDA INTERNATIONAL UNIVERSITY

Ai multi-domain integrated system and method for automatic generation of cyber crisis scenario

There is provided a method for automatically generating a cyber crisis scenario, performed by a computing system. The method may comprise classifying types of content included in a cyber crisis report and extracting image data and text data from the cyber crisis report, inputting the image data into an image processing model and extracting attack procedure / behavior information included in the image data, inputting the text data into a text processing model and generating structured attack procedure-related data from each attack procedure included in the text data, generating threat behavior data corresponding to the attack procedure-related data, and merging the threat behavior data with the attack procedure-related data, matching the attack procedure-related data to the attack procedure / behavior information and generating a cyber crisis scenario template and automatically generating a cyber crisis scenario based on the attack procedure-related data and the cyber crisis scenario template.
Owner:KOREA INTERNET & SECURITY AGENCY

Cable tunnel anti-theft and anti-external damage monitoring subsystem and monitoring method thereof

The invention discloses an anti-theft and anti-external damage monitoring subsystem for a cable tunnel and a monitoring method of the anti-theft and anti-external damage monitoring subsystem. According to the system, distributed optical fiber sound wave sensing networks are deployed in a tunnel and underground above the tunnel, and a ground pulsation sensor array in the tunnel is combined. The system adopts a multi-mode threat recognition AI engine, vibration and sound wave signals are classified and recognized through a deep learning model combining a one-dimensional convolutional neural network and a long-short-term memory network, and a threat position and a behavior mode are judged by utilizing a space-time correlation analysis engine. The system further comprises a threat level comprehensive evaluation model which can output quantitative threat indexes and trigger a hierarchical alarm mechanism, and meanwhile, the intelligent video rechecking unit is linked to carry out visual confirmation. According to the invention, accurate identification, accurate positioning and intelligent early warning of threat behaviors inside and outside the tunnel are realized, the problems of high false alarm rate and early warning lag of a traditional monitoring system are effectively solved, and the safety protection level of the cable tunnel is obviously improved.
Owner:SANYE ELECTRIC CO LTD

A pipeline threat behavior identification method and device and a storage medium

The application discloses a pipeline threat behavior identification method and device and a storage medium, and relates to the technical field of machine vision. The method comprises the following steps: acquiring a to-be-detected video photographed by unmanned aerial vehicle inspection; performing target detection on image frames of the to-be-detected video, determining target detection boxes of detection objects in the image frames and target categories of the detection objects; performing trajectory tracking on the target detection boxes to obtain target trajectories of the detection objects; extracting behavior features of the detection objects, wherein the behavior features comprise morphological change features of the detection boxes and trajectory features of the target trajectories of the detection objects; and identifying pipeline threat behaviors of the detection objects based on the target categories, the behavior features of the detection objects and a pre-trained classification model. The method can effectively detect small targets such as personnel and vehicles, effectively determine threat behaviors such as personnel loitering, personnel digging and mechanical digging, and the algorithm has the light-weight feature.
Owner:PIPECHINA SOUTH CHINA CO +1

Threat mitigation for vehicles

ActiveCN114630777Bactivate visual deterrentsActivation of auditory deterrentsControl cellTransport engineering
A method for controlling a vehicle is disclosed. The method comprises determining whether one or more surrounding vehicles exhibit a threatening behavior, and controlling the vehicle to perform one or more threat-avoidance actions when it is determined that one or more surrounding vehicles exhibit a threatening behavior. Example threatening behaviors include a first surrounding vehicle directly in front of the vehicle decelerating without a traffic-related reason for deceleration, and, in combination with the former, a second surrounding vehicle in a lane adjacent to the vehicle decelerating in association with the first surrounding vehicle. Corresponding computer programs, computer program products, control units, devices, systems, and vehicles are also disclosed.
Owner:NINGBO GEELY AUTOMOBILE RES & DEV CO LTD

Network security test and evaluation system and method

The invention belongs to the technical field of network security, and discloses a network security test and evaluation system and method, and the system comprises an asset and topology automatic discovery module, a threat behavior simulation and attack chain generation module, a security configuration difference analysis module, a risk quantification and evaluation module, and a linkage protection and verification module. The system recognizes network assets and the dependency relationship thereof through passive traffic analysis and active exploration, generates an attack surface model based on an asset structure, constructs a candidate attack chain by using a heuristic search method, and executes threat simulation operation in a controlled environment. The system can also perform difference analysis on the actual configuration of the target asset and the baseline, calculate a risk index in combination with a simulation result, and automatically trigger a protection measure and verify the effectiveness when the risk reaches a threshold value. According to the method, continuous, real and reproducible security assessment can be realized in a complex network environment, and the risk discovery capability and the reliability of a protection strategy are improved.
Owner:李师谦

AI-based cybersecurity system trained with multimodal large models

ActiveCN120281550BImprove fault prediction accuracyImprove attack detection accuracyKey distribution for secure communicationUser identity/authority verificationAttackMultidimensional data
This invention relates to the field of intelligent security operation and maintenance technology, specifically to an artificial intelligence network security system based on multimodal large model training. The system includes a server fault diagnosis module, a network attack detection module, an endpoint security monitoring module, a key management optimization module, and a threat analysis feedback module. In this invention, multidimensional data analysis improves the accuracy of fault prediction, reducing business interruptions caused by sudden hardware failures. Based on server anomaly assessment, network access frequency, source, and command characteristics are evaluated to improve attack detection accuracy and reduce the risk of false positives. Endpoint device execution behavior, resource calls, and behavior sequences are extracted to achieve fine-grained security monitoring, enhancing attack tracing capabilities. Key policies are dynamically adjusted to improve security adaptability and reduce policy lag risks. Multi-level data is integrated to calculate the fit between threat behavior and attack, enhancing the precision and response speed of threat assessment and improving overall security situation awareness.
Owner:SHENZHEN JINCHAO CLOUD CONTROL TECH CO LTD

Vehicle sentry mode threat early warning method and system and vehicle

PendingCN121963440ASolve the problem of low accuracy in identifying threat intentDetection of traffic movementBiological modelsEngineeringThreat level
The invention relates to the technical field of vehicles, in particular to a vehicle sentry mode threat early warning method and system and a vehicle. The method comprises the following steps: acquiring multi-mode sensing data acquired from the periphery of a vehicle body in a sentry mode; extracting key features of each mode in the multi-mode sensing data through an adaptive backbone network to obtain a multi-mode feature sequence; inputting the multi-modal feature sequence into a cross-modal feature interaction fusion module to generate an advanced semantic feature sequence containing threat behavior information; inputting the high-level semantic feature sequence into a high-level semantic reasoning module so as to carry out mixed decision making by utilizing a propagation algorithm based on a causal graph and a symbolized behavior rule knowledge base, and outputting a multi-dimensional behavior intention result; according to the method, quantitative threat assessment is executed according to a multi-dimensional behavior intention result, threat levels of multiple levels are output, differentiated early warning and response strategies are triggered based on the threat levels, and the problem that the potential threat intention recognition accuracy of an existing method is low can be effectively solved.
Owner:BEI DOU ZHI LIAN KE JI YOU XIAN GONG SI

A cyber-security incident handling and assessment system

This invention relates to the field of cybersecurity technology, specifically to a network security incident handling and assessment system. Based on an internet security protection system, this invention collects traffic and identifies threat behaviors from various security protection products such as situational awareness and cloud defense. Upon detecting a security incident, it issues an alert, prompting operations and maintenance (O&M) personnel to take action. The effectiveness of the handling methods is then evaluated, and highly-rated methods are tagged and stored in a method library. When similar security incidents occur again, appropriate handling methods are recommended based on the matching results, assisting O&M personnel in decision-making. Finally, historical data on the security incident handling process is statistically analyzed and displayed in a radar chart format, showing the O&M personnel's skills in dealing with attack threats. This not only allows O&M personnel to continuously iterate their handling plans for various security incidents to obtain optimal solutions, but also presents the O&M personnel's skill level graphically, achieving the purpose of identifying gaps in knowledge and targeted improvement.
Owner:THE 54TH RESEARCH INSTITUTE OF CHINA ELECTRONICS TECHNOLOGY GROUP CORPORATION

A method, apparatus, equipment and storage medium for producing threat intelligence

This invention discloses a method, apparatus, device, and storage medium for producing threat intelligence, applied in the field of network security. The method includes: acquiring raw threat information corresponding to IPs without threat intelligence within a preset time period; aggregating the raw threat information based on the IPs to obtain aggregated raw threat information; extracting features from the aggregated raw threat information to obtain feature vectors; inputting the feature vectors into a trained neural network model; if the IPs exhibit threatening behavior, determining the threat type of the IPs based on the trained neural network model, and producing corresponding threat intelligence based on the threat type. Compared to existing technologies that produce intelligence based on processed data analysis, this method directly utilizes machine learning technology to analyze raw threat information, ensuring the accuracy of threat intelligence production. Furthermore, the threat intelligence produced by this method can be directly applied to security devices, facilitating subsequent security monitoring.
Owner:HANGZHOU DBAPPSECURITY CO LTD

Artificial intelligence-based security detection method, device and storage medium

The application discloses an artificial intelligence-based security detection method and device and a storage medium, and belongs to the technical field of security detection. The method comprises the following steps: acquiring security event data of a detection point, comparing and analyzing the security event data with a preset threat behavior mode through a threat correlation knowledge model, obtaining the correlation between the security event data, matching the entity path of the correlation in a security knowledge graph with a preset threat chain mode, determining a threat event chain according to the matching result, and triggering a security protection mechanism according to the threat analysis result corresponding to the threat event chain. According to the application, the correlation between different threat events is recognized, and the efficiency and accuracy of the threat response of the security detection system are improved.
Owner:ZHEJIANG COMM SERVICES

Network security analysis system and method based on security situation awareness system

InactiveCN121967013AEliminate technical barriersimprove data qualitySecuring communicationTimestampOriginal data
The invention discloses a network security analysis system and method based on a security situation awareness system, and relates to the technical field of network security situation awareness, and the system comprises a data collection module, a processing module, an event reconstruction module, a threat analysis module and a situation generation module which cooperate in sequence. The data acquisition module acquires original data containing encrypted traffic and unstructured alarm from a network boundary probe; the data processing module performs hierarchical decoding and normalization on the data to generate a standardized record with a unified timestamp; the event reconstruction module connects the records into a continuous event sequence according to a time sequence; the threat analysis module compares the event sequence with a threat behavior pattern library, and identifies and marks fragments conforming to an attack chain; and the situation generation module constructs a network security situation portrait accordingly. According to the scheme, effective analysis of encrypted and unstructured security data is realized, a complex and latent attack behavior chain can be identified based on the continuous event sequence, and the depth and accuracy of threat detection are improved.
Owner:INFORMATION & COMM CO OF STATE GRID SHAANXI ELECTRIC POWER CO LTD

A virtual-real combined industrial control software security test platform

The application discloses a kind of industrial control software security test platform based on virtual and real combination, it is related to industrial control system safety testing technical field, including: test monitoring sub-platform, for centralized control simulation environment and test tool operation, to test environment, measured object and threat behavior are visualized output, and record, analyze test data to quantize evaluation security risk;Security test tool set, for monitoring the state parameters of industrial control system and detecting the abnormal behavior of industrial control system, and performing threat injection test;Security information base, for storing the defect information base of industrial control system, hardware and software vulnerability library, network protocol feature library and test case library;Simulation running environment, for building the complete running environment of industrial control system through simulation means.The application supports the interactive test of physical equipment and virtual MES, can simulate bandwidth limit, packet loss rate and other real industrial network environment, improve the credibility of test result.
Owner:INFORMATION CENT OF CHINA NORTH IND GRP

Information intelligent early warning system and method based on big data security analysis

The invention discloses an intelligent information early warning system and method based on big data security analysis, and relates to the technical field of network security. According to the method, the candidate feature fragments are extracted from the historical standard security data flow through the feature extraction network, the candidate feature fragments are mutually matched through the collaborative matching mechanism, then the security event fragments are generated, the security event fragments are marked as the atomic security features, and the atomic security features are clustered and fused to generate the composite security feature. The method comprises the following steps: traversing all historical standard security data streams through composite security features to extract feature data fragments, sorting the feature data fragments to generate a multi-dimensional threat feature matrix, establishing threat behavior association trees according to the multi-dimensional threat feature matrix, matching the threat behavior association trees and connecting the threat behavior association trees with a global threat feature forest to obtain a threat behavior association tree; and converting the standard security data generated in real time into a detection feature sub-matrix, inputting the detection feature sub-matrix into the forest for matching analysis, and outputting a security early warning report.
Owner:ZHONGZHI INTELLIGENT MANUFACTURING (SHANDONG) INTELLIGENT TECHNOLOGY CO LTD

Threat behavior spectrum representation method and apparatus

The application provides a threat behavior spectrum representation method and device, the method comprises the following steps: clustering network attack and vulnerability sample data set according to a clustering algorithm to obtain a plurality of unknown threat clusters, wherein the network attack and vulnerability sample data set comprises a plurality of network attack and vulnerability sample data with cross relationship and a plurality of network attack and vulnerability sample data without cross relationship; inputting each unknown threat cluster into a GNN model which is trained based on a plurality of historical unknown threat clusters in advance, so that the GNN model extracts the network element information of the overall feature space corresponding to each unknown threat cluster; and mapping the network element information of each overall feature space into a threat behavior spectrum according to a graph embedding spectrum representation algorithm. The application can improve the network malicious behavior recognition efficiency, simplify the model structure, improve the model practicability, and unify the management of network malicious behaviors to improve the comprehensiveness of network malicious behavior representation.
Owner:BEIJING UNIV OF POSTS & TELECOMM +1

Method for detecting and analyzing time-series data based on cyber threat framework

This disclosure details a method for detecting and analyzing time-series data with a cyber threat framework. It involves determining target API events, mapping these to threat behaviors, creating threat scenarios, assessing matching degree and risk, predicting threat behaviors based on risk grades, and providing solutions.
Owner:ASTRON SECURITY INC

Threat behavior association analysis method for power network security situation awareness

PendingCN121864355AEnhance the ability of core functions to function properlySecuring communicationAttackCorrelation analysis
The invention is suitable for the technical field of power network security, and provides a threat behavior association analysis method for power network security situation awareness, and the method comprises the steps: obtaining IT side data and OT side data in a power network; after processing, generating a standardized security event sequence; matching the standardized security event sequence with a plurality of preset association analysis rules; the correlation analysis rule is used for defining causal, time sequence and logic relationships among different types of security events; generating at least one threat behavior event according to the matching result; according to the generated threat behavior event type and risk level, generating a corresponding power system alarm signal; and sending the generated power system alarm signal to an alarm device to execute early warning feedback. According to the method, an ongoing attack and a possible target can be identified, an abstract network security threat is converted into a specific risk value or grade, and the capability of maintaining normal operation of a core function after the power network is subjected to the network attack is enhanced.
Owner:GUANGXI POWER GRID CORP